PT-2016-2300 · Apache · Apache Struts

Adam Mariš

·

Published

2016-07-04

·

Updated

2022-05-17

·

CVE-2016-4465

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Apache Struts versions 2.3.20 through 2.3.28.1 Apache Struts versions 2.5.x before 2.5.13
Description The issue exists due to insufficient input validation in the URLValidator class of Apache Struts. This allows a remote attacker to cause a denial of service by providing a null value for a URL field.
Recommendations For Apache Struts versions 2.3.20 through 2.3.28.1, update to a version outside of this range to resolve the issue. For Apache Struts versions 2.5.x before 2.5.13, update to version 2.5.13 or later to resolve the issue. As a temporary workaround, consider restricting the input for URL fields to prevent null values from being processed by the URLValidator class.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-01689
CVE-2016-4465
GHSA-XG75-68X3-7P3Q

Affected Products

Apache Struts