CVE-2017-7672

MEDIUM

Apache Struts <2.5.12 - DoS

Title source: llm

Description

If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Solution is to upgrade to Apache Struts version 2.5.12.

Scores

CVSS v3 5.9
EPSS 0.0135
EPSS Percentile 79.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-20
Status published
Products (9)
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
org.apache.struts/struts2-core < 2.5.12Maven
Apache Software Foundation/Apache Struts < 2.5 to 2.5.10.1
Published Jul 13, 2017
Tracked Since Feb 18, 2026