Re: [ANN] CVE-2025-64775: Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS) - S2-068

David Brunstein <[email protected]> Fri, 5 Dec 2025 08:19:47 -0600
Newsgroups gmane.comp.jakarta.struts.user
Message-ID <CAKxUg_W=-VuVX9G9qS_chiHo0NSX2HNcAsS4sNTe1aoRScFATw@mail.gmail.com>
--000000000000cdd2db0645352427
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Oh! Thank you again for your clarification, Lukasz.

Davo


On Fri, Dec 5, 2025 at 1:53=E2=80=AFAM Lukasz Lenart <[email protected]=
rg>
wrote:

> pt., 5 gru 2025 o 08:35 David Brunstein <[email protected]>
> napisa=C5=82(a):
> > S2-068
> > https://cwiki.apache.org/confluence/display/WW/S2-068
> >
> > Under the Solution section, the page stands "Upgrade to Struts 6.8.0",
> should it be updated to "Upgrade to Struts 6.7.0"?
>
> No, this is fine, CVE is addressed in 6.8.0 or 7.1.1, the only missing
> point is: 6.7.4 is also affected - I already updated the bulletin
>
> Cheers
> =C5=81ukasz
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
>
>

--000000000000cdd2db0645352427--