URL Validation Vulnerability in Apache Struts by The Apache Software Foundation
CVE-2016-8738

5.9MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
20 September 2017

Summary

In versions of Apache Struts from 2.5 to 2.5.5, an application susceptible to this vulnerability may expose itself to a denial of service attack through improper handling of URL input. If an application utilizes the built-in URLValidator without adequate checks, an attacker could craft a malicious URL that, when validated, could cause the server to become unresponsive. This poses significant risks to web application integrity and availability, thereby necessitating prompt remediation.

Affected Version(s)

Apache Struts 2.5 - 2.5.5

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.