Re: [ANN] CVE-2025-64775: Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS) - S2-068
David Brunstein <[email protected]> Fri, 5 Dec 2025 01:30:26 -0600
| Newsgroups | gmane.comp.jakarta.struts.user |
|---|---|
| Message-ID | <CAKxUg_XvUGRM=3suA2O3O4+hJaHiLL=vFV6SvZoQGDcP7j05UA@mail.gmail.com> |
--000000000000f059e806452f6cb3 Content-Type: multipart/alternative; boundary="000000000000f059e706452f6cb2" --000000000000f059e706452f6cb2 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hi Lukasz, Thank you for your confirmation. S2-068 https://cwiki.apache.org/confluence/display/WW/S2-068 Under the Solution section, the page stands "Upgrade to Struts 6.8.0", should it be updated to "Upgrade to Struts 6.7.0"? [image: image.png] Thanks, Davo On Fri, Dec 5, 2025 at 12:17=E2=80=AFAM =C5=81ukasz Lenart <lukasz.lenart@g= mail.com> wrote: > I missed 6.7.4, sorry, my bad :( Any version above 6.7.x is fine. > > czw., 4 gru 2025 o 21:36 David Brunstein <[email protected]> > napisa=C5=82(a): > > > > I am looking into CVE-2025-64775, and which Apache Struts2 versions are > > affected. > > > > My findings on the web are inconsistent. Lukasz, can you confirm that > this > > would not affect versions of Struts 6 above Struts 6.7.0? > > > > Thank you, > > Davo > > > > On Mon, Dec 1, 2025 at 8:45=E2=80=AFAM Lukasz Lenart <lukaszlenart@apac= he.org> > > wrote: > > > > > Severity: important > > > > > > Affected versions: > > > > > > - Apache Struts (org.apache.struts:struts2-core) 2.0.0 through 6.7.0 > > > - Apache Struts (org.apache.struts:struts2-core) 7.0.0 through 7.0.3 > > > > > > Description: > > > > > > Denial of Service vulnerability in Apache Struts, file leak in > > > multipart request processing causes disk exhaustion. > > > > > > This issue affects Apache Struts: from 2.0.0 through 6.7.0, from 7.0.= 0 > > > through 7.0.3. > > > > > > Users are recommended to upgrade to version 6.8.0 or 7.1.1, which > > > fixes the issue. > > > > > > Credit: > > > > > > Nicolas Fournier (reporter) > > > > > > References: > > > > > > https://cwiki.apache.org/confluence/display/WW/S2-068 > > > https://struts.apache.org/ > > > https://www.cve.org/CVERecord?id=3DCVE-2025-64775 > > > > > > > > > On behalf of the Apache Struts project > > > =C5=81ukasz Lenart > > > > > > --------------------------------------------------------------------- > > > To unsubscribe, e-mail: [email protected] > > > For additional commands, e-mail: [email protected] > > > > > > > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [email protected] > For additional commands, e-mail: [email protected] > > --000000000000f059e706452f6cb2 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">Hi Lukasz,<div><br></div><div>Thank you for your confirmat= ion.</div><div><br></div><div>S2-068</div><div><a href=3D"https://cwiki.apa= che.org/confluence/display/WW/S2-068">https://cwiki.apache.org/confluence/d= isplay/WW/S2-068</a></div><div><br></div><div>Under the Solution section, t= he page stands "Upgrade to Struts 6.8.0", should it be updated to= "Upgrade to Struts 6.7.0"?<br><br><img src=3D"cid:ii_misjoc3n0" = alt=3D"image.png" width=3D"504" height=3D"562"></div><div><br></div><div>Th= anks,</div><div>Davo</div><div><br><br><br></div><div><br></div><div><br></= div><div><br></div></div><br><div class=3D"gmail_quote gmail_quote_containe= r"><div dir=3D"ltr" class=3D"gmail_attr">On Fri, Dec 5, 2025 at 12:17=E2=80= =AFAM =C5=81ukasz Lenart <<a href=3D"mailto:[email protected]">luk= [email protected]</a>> wrote:<br></div><blockquote class=3D"gmail_quo= te" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204= );padding-left:1ex">I missed 6.7.4, sorry, my bad :( Any version above 6.7.= x is fine.<br> <br> czw., 4 gru 2025 o 21:36 David Brunstein <<a href=3D"mailto:davidbrunste= [email protected]" target=3D"_blank">[email protected]</a>> napisa=C5= =82(a):<br> ><br> > I am looking into CVE-2025-64775, and which Apache Struts2 versions ar= e<br> > affected.<br> ><br> > My findings on the web are inconsistent. Lukasz, can you confirm that = this<br> > would not affect versions of Struts 6 above Struts 6.7.0?<br> ><br> > Thank you,<br> > Davo<br> ><br> > On Mon, Dec 1, 2025 at 8:45=E2=80=AFAM Lukasz Lenart <<a href=3D"ma= ilto:[email protected]" target=3D"_blank">[email protected]</a>= ><br> > wrote:<br> ><br> > > Severity: important<br> > ><br> > > Affected versions:<br> > ><br> > > - Apache Struts (org.apache.struts:struts2-core) 2.0.0 through 6.= 7.0<br> > > - Apache Struts (org.apache.struts:struts2-core) 7.0.0 through 7.= 0.3<br> > ><br> > > Description:<br> > ><br> > > Denial of Service vulnerability in Apache Struts, file leak in<br= > > > multipart request processing causes disk exhaustion.<br> > ><br> > > This issue affects Apache Struts: from 2.0.0 through 6.7.0, from = 7.0.0<br> > > through 7.0.3.<br> > ><br> > > Users are recommended to upgrade to version 6.8.0 or 7.1.1, which= <br> > > fixes the issue.<br> > ><br> > > Credit:<br> > ><br> > > Nicolas Fournier (reporter)<br> > ><br> > > References:<br> > ><br> > > <a href=3D"https://cwiki.apache.org/confluence/display/WW/S2-068"= rel=3D"noreferrer" target=3D"_blank">https://cwiki.apache.org/confluence/d= isplay/WW/S2-068</a><br> > > <a href=3D"https://struts.apache.org/" rel=3D"noreferrer" target= =3D"_blank">https://struts.apache.org/</a><br> > > <a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-64775" rel= =3D"noreferrer" target=3D"_blank">https://www.cve.org/CVERecord?id=3DCVE-20= 25-64775</a><br> > ><br> > ><br> > > On behalf of the Apache Struts project<br> > > =C5=81ukasz Lenart<br> > ><br> > > -----------------------------------------------------------------= ----<br> > > To unsubscribe, e-mail: <a href=3D"mailto:user-unsubscribe@struts= .apache.org" target=3D"_blank">[email protected]</a><br> > > For additional commands, e-mail: <a href=3D"mailto:user-help@stru= ts.apache.org" target=3D"_blank">[email protected]</a><br> > ><br> > ><br> <br> ---------------------------------------------------------------------<br> To unsubscribe, e-mail: <a href=3D"mailto:[email protected]= g" target=3D"_blank">[email protected]</a><br> For additional commands, e-mail: <a href=3D"mailto:[email protected].= org" target=3D"_blank">[email protected]</a><br> <br> </blockquote></div> --000000000000f059e706452f6cb2-- --000000000000f059e806452f6cb3--