CVE-2017-7672
MEDIUMApache Struts <2.5.12 - DoS
Title source: llmDescription
If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Solution is to upgrade to Apache Struts version 2.5.12.
References (6)
Scores
CVSS v3
5.9
EPSS
0.0135
EPSS Percentile
79.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-20
Status
published
Products (9)
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
org.apache.struts/struts2-core
< 2.5.12Maven
Apache Software Foundation/Apache Struts
< 2.5 to 2.5.10.1
Published
Jul 13, 2017
Tracked Since
Feb 18, 2026