Apache Struts
cpe:2.3:a:apache:struts:*:*:*:*:*:*:*
- >= 2.0.0, <= 2.3.37
- >= 2.5.0, <= 2.5.33
- >= 6.0.0, <= 6.7.0
- >= 7.0.0, <= 7.0.3
A denial-of-service vulnerability has been identified in Apache Struts versions 2.0.0 through 6.7.0 and 7.0.0 through 7.0.3. The issue arises from a file leak during multipart request processing, leading to disk exhaustion. Users are advised to upgrade to version 6.8.0 or 7.1.1, which address this vulnerability.
Exploitation of this vulnerability causes disk exhaustion, leading to a denial-of-service condition.
Users should upgrade to Apache Struts version 6.8.0 or 7.1.1.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.