Re: [ANN] CVE-2025-64775: Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS) - S2-068
David Brunstein <[email protected]> Fri, 5 Dec 2025 08:19:47 -0600
| Newsgroups | gmane.comp.jakarta.struts.user |
|---|---|
| Message-ID | <CAKxUg_W=-VuVX9G9qS_chiHo0NSX2HNcAsS4sNTe1aoRScFATw@mail.gmail.com> |
--000000000000cdd2db0645352427 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Oh! Thank you again for your clarification, Lukasz. Davo On Fri, Dec 5, 2025 at 1:53=E2=80=AFAM Lukasz Lenart <[email protected]= rg> wrote: > pt., 5 gru 2025 o 08:35 David Brunstein <[email protected]> > napisa=C5=82(a): > > S2-068 > > https://cwiki.apache.org/confluence/display/WW/S2-068 > > > > Under the Solution section, the page stands "Upgrade to Struts 6.8.0", > should it be updated to "Upgrade to Struts 6.7.0"? > > No, this is fine, CVE is addressed in 6.8.0 or 7.1.1, the only missing > point is: 6.7.4 is also affected - I already updated the bulletin > > Cheers > =C5=81ukasz > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [email protected] > For additional commands, e-mail: [email protected] > > --000000000000cdd2db0645352427--