S2-064: CVE-2023-34396: Apache Struts: DoS via OOM owing to no sanity limit on normal form fields in multipart forms
Yasser Zamani <[email protected]> Wed, 14 Jun 2023 07:35:56 +0000
| Newsgroups | gmane.comp.security.bugtraq,gmane.comp.jakarta.struts.announce,gmane.comp.jakarta.log4j.devel,gmane.comp.apache.maven.announce,gmane.comp.java.hadoop.zookeeper.user,gmane.comp.security.full-disclosure |
|---|---|
| Message-ID | <5dbcacaa-d162-07a3-5e3f-d66259320b20__12313.3056725905$1686728401$gmane$org@apache.org> |
Affected versions: - Apache Struts through 2.5.30 - Apache Struts through 6.1.2 Description: Allocation of Resources Without Limits or Throttling vulnerability in = Apache Software Foundation Apache Struts.This issue affects Apache Struts: = through 2.5.30, through 6.1.2. Credit: Matthew McClain (finder) References: https://cwiki.apache.org/confluence/display/WW/S2-064 https://struts.apache.org/ https://www.cve.org/CVERecord?id=3DCVE-2023-34396