Re: [ANN] CVE-2025-64775: Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS) - S2-068

Ggg Nnn <[email protected]> Sat, 6 Dec 2025 15:43:18 +0200
Newsgroups gmane.comp.jakarta.struts.user
Message-ID <CAN-5gZ9MQ0YQRtiKof3e_9QJ0-64rrPpB75M9OyGKiuvfHQ81A@mail.gmail.com>
--000000000000571a85064548980a
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Thank you very much, =C5=81ukasz! Your quick answer was very helpful and a =
real
relief =3D)

Have a great weekend!
Georgi


On Sat, 6 Dec 2025, 10:59 Lukasz Lenart, <[email protected]> wrote:

> pt., 5 gru 2025 o 18:25 Ggg Nnn <[email protected]> napisa=C5=82(a):
> > Are Struts 6.x client applications vulnerable in case they do not rely
> > on file uploads feature and they have explicitly disabled file upload
> > support via struts.multipart.enabled config property (as explained in
> >
> https://struts.apache.org/core-developers/action-file-upload#disabling-fi=
le-upload-support
> )?
>
> No, if file upload support is disabled, your application is not
> vulnerable. I updated the bulletin.
>
> Cheers
> =C5=81ukasz
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
>
>

--000000000000571a85064548980a--