CVE-2017-7672
published 2017-07-13CVE-2017-7672: If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload…
PriorityP336medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
9.36%
94.9th percentile
If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Solution is to upgrade to Apache Struts version 2.5.12.
Affected
54 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
ghsa5.9MEDIUM
osv5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
struts: A regular expression Denial of Service when using URLValidator
vendor_redhat·2017-09-05·CVSS 5.9
CVE-2017-9804 [MEDIUM] CWE-20 struts: A regular expression Denial of Service when using URLValidator
struts: A regular expression Denial of Service when using URLValidator
In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. NOTE: this vulnerability exists because of an incomplete fix for S2-047 / CVE-2017-7672.
Statement: A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in any Red Hat provided final products, and does not cause any vulnerability in the product, struts2-c
Red Hat
struts: Denial of service in built-in URLValidator
vendor_redhat·2017-08-11·CVSS 5.9
CVE-2017-7672 [MEDIUM] CWE-20 struts: Denial of service in built-in URLValidator
struts: Denial of service in built-in URLValidator
If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Solution is to upgrade to Apache Struts version 2.5.12.
Statement: A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in any Red Hat provided final products, and does not cause any vulnerability in the product, struts2-core jars have been included in some products' source code packages. The inclusion was part of an import of the Google
OSV
Apache Struts Improper Input Validation vulnerability
osv·2018-10-16
CVE-2017-7672 [MEDIUM] Apache Struts Improper Input Validation vulnerability
Apache Struts Improper Input Validation vulnerability
If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Solution is to upgrade to Apache Struts version 2.5.12.
OSV
Apache Struts allows entering a custom URL in a form field if built-in URLValidator is used
osv·2018-10-16·CVSS 5.9
CVE-2017-9804 [MEDIUM] Apache Struts allows entering a custom URL in a form field if built-in URLValidator is used
Apache Struts allows entering a custom URL in a form field if built-in URLValidator is used
In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. NOTE: this vulnerability exists because of an incomplete fix for S2-047 / CVE-2017-7672.
GHSA
Apache Struts Improper Input Validation vulnerability
ghsa·2018-10-16
CVE-2017-7672 [MEDIUM] CWE-20 Apache Struts Improper Input Validation vulnerability
Apache Struts Improper Input Validation vulnerability
If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Solution is to upgrade to Apache Struts version 2.5.12.
GHSA
Apache Struts allows entering a custom URL in a form field if built-in URLValidator is used
ghsa·2018-10-16·CVSS 5.9
CVE-2017-9804 [MEDIUM] CWE-20 Apache Struts allows entering a custom URL in a form field if built-in URLValidator is used
Apache Struts allows entering a custom URL in a form field if built-in URLValidator is used
In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. NOTE: this vulnerability exists because of an incomplete fix for S2-047 / CVE-2017-7672.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-9804 struts: A regular expression Denial of Service when using URLValidator
bugzilla·2017-09-05·CVSS 5.9
CVE-2017-9804 [MEDIUM] CVE-2017-9804 struts: A regular expression Denial of Service when using URLValidator
CVE-2017-9804 struts: A regular expression Denial of Service when using URLValidator
The previous fix issued with S2-047 (CVE-2017-7672) was incomplete. If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL.
Affected versions:
Struts 2.3.7 - Struts 2.3.33, Struts 2.5 - Struts 2.5.12
External References:
https://struts.apache.org/docs/s2-050.html
Discussion:
Statement:
A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in any Red Hat
Bugzilla
CVE-2017-7672 struts: Denial of service in built-in URLValidator [fedora-all]
bugzilla·2017-08-11·CVSS 5.9
CVE-2017-7672 [MEDIUM] CVE-2017-7672 struts: Denial of service in built-in URLValidator [fedora-all]
CVE-2017-7672 struts: Denial of service in built-in URLValidator [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2017-7672 struts: Denial of service in built-in URLValidator
bugzilla·2017-08-11·CVSS 5.9
CVE-2017-7672 [MEDIUM] CVE-2017-7672 struts: Denial of service in built-in URLValidator
CVE-2017-7672 struts: Denial of service in built-in URLValidator
A flaw was found in Apache Struts 2.5 through 2.5.10.1. If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL.
References:
http://struts.apache.org/docs/s2-047.html
https://lists.apache.org/thread.html/3795c4dd46d9ec75f4a6eb9eca11c11edd3e796c6c1fd7b17b5dc50d@%3Cannouncements.struts.apache.org%3E
Discussion:
Created struts tracking bugs for this issue:
Affects: epel-7 [bug 1480616]
Affects: fedora-all [bug 1480615]
---
0ps ... Sorry
---
Statement:
A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not includ
Bugzilla
CVE-2017-7672 struts: Denial of service in built-in URLValidator [epel-7]
bugzilla·2017-08-11·CVSS 5.9
CVE-2017-7672 [MEDIUM] CVE-2017-7672 struts: Denial of service in built-in URLValidator [epel-7]
CVE-2017-7672 struts: Denial of service in built-in URLValidator [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpkg u
http://struts.apache.org/docs/s2-047.htmlhttp://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.htmlhttp://www.securityfocus.com/bid/99563http://www.securitytracker.com/id/1039114https://lists.apache.org/thread.html/3795c4dd46d9ec75f4a6eb9eca11c11edd3e796c6c1fd7b17b5dc50d%40%3Cannouncements.struts.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20180706-0002/http://struts.apache.org/docs/s2-047.htmlhttp://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.htmlhttp://www.securityfocus.com/bid/99563http://www.securitytracker.com/id/1039114https://lists.apache.org/thread.html/3795c4dd46d9ec75f4a6eb9eca11c11edd3e796c6c1fd7b17b5dc50d%40%3Cannouncements.struts.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20180706-0002/
2017-07-13
Published