PT-2017-9773 · Apache · Apache Struts

Publicado

2017-09-20

·

Atualizado

2022-05-14

·

CVE-2016-8738

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache Struts versions 2.5 through 2.5.5
Description The issue allows an attacker to prepare a special URL that can overload the server process when the built-in URLValidator is used to validate the URL. This can happen if an application allows entering a URL in a form field.
Recommendations For Apache Struts versions 2.5 through 2.5.5, consider disabling the built-in URLValidator until a patch is available to prevent potential server overload. Restrict access to form fields that allow URL entry to minimize the risk of exploitation.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-8738
GHSA-86VQ-8QHC-5RQW

Produtos afetados

Apache Struts