Remote Code Execution Vulnerability in Apache Struts by Apache
CVE-2017-7672
5.9MEDIUM
What is CVE-2017-7672?
A vulnerability exists in Apache Struts when the application permits users to input URLs via form fields without adequate validation. When the built-in URLValidator is engaged, it can lead to the processing of a specially crafted URL that may overload the server during the validation process. To mitigate this risk, users are advised to upgrade to Apache Struts version 2.5.12, which addresses this critical issue.
Affected Version(s)
Apache Struts 2.5 to 2.5.10.1