S2-063: CVE-2023-34149: Apache Struts: DoS via OOM owing to not properly checking of list bounds

Yasser Zamani <[email protected]> Wed, 14 Jun 2023 07:34:50 +0000
Newsgroups gmane.comp.security.full-disclosure,gmane.comp.apache.maven.announce,gmane.comp.security.bugtraq,gmane.comp.jakarta.struts.announce,gmane.comp.clustering.spark.livy.devel,gmane.comp.jakarta.lucene.net.user
Message-ID <c6656261-e9f3-cc4e-e305-7e5801afb70a__49617.5705151231$1686728388$gmane$org@apache.org>
Affected versions:

- Apache Struts through 2.5.30
- Apache Struts through 6.1.2

Description:

Allocation of Resources Without Limits or Throttling vulnerability in =
Apache Software Foundation Apache Struts.This issue affects Apache Struts: =
through 2.5.30, through 6.1.2.

Credit:

Matthew McClain (finder)

References:

https://cwiki.apache.org/confluence/display/WW/S2-063
https://struts.apache.org/
https://www.cve.org/CVERecord?id=3DCVE-2023-34149