Re: [ANN] CVE-2025-64775: Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS) - S2-068
Lukasz Lenart <[email protected]> Fri, 5 Dec 2025 08:50:31 +0100
| Newsgroups | gmane.comp.jakarta.struts.user |
|---|---|
| Message-ID | <CAMopvkNcEkkhx8VwBUXZzmPDsTE7QNLNdD1PRkSoV_kPbG4nsg@mail.gmail.com> |
pt., 5 gru 2025 o 08:35 David Brunstein <[email protected]> napisa= =C5=82(a): > S2-068 > https://cwiki.apache.org/confluence/display/WW/S2-068 > > Under the Solution section, the page stands "Upgrade to Struts 6.8.0", sh= ould it be updated to "Upgrade to Struts 6.7.0"? No, this is fine, CVE is addressed in 6.8.0 or 7.1.1, the only missing point is: 6.7.4 is also affected - I already updated the bulletin Cheers =C5=81ukasz