The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2017-09-20 17:29
Updated : 2025-04-20 01:37
NVD link : CVE-2017-9793
Mitre link : CVE-2017-9793
CVE.ORG link : CVE-2017-9793
JSON object : View
Products Affected
apache
- struts
CWE
CWE-20
Improper Input Validation