S2-063: CVE-2023-34149: Apache Struts: DoS via OOM owing to not properly checking of list bounds
Yasser Zamani <[email protected]>
| Newsgroups | gmane.comp.jakarta.struts.devel |
|---|---|
| Message-ID | <c6656261-e9f3-cc4e-e305-7e5801afb70a__16532.2555157886$1686728153$gmane$org@apache.org> |
Affected versions: - Apache Struts through 2.5.30 - Apache Struts through 6.1.2 Description: Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: through 2.5.30, through 6.1.2. Credit: Matthew McClain (finder) References: https://cwiki.apache.org/confluence/display/WW/S2-063 https://struts.apache.org/ https://www.cve.org/CVERecord?id=CVE-2023-34149