CVE-2017-9804
published 2017-09-20CVE-2017-9804: In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is…
PriorityP344high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
8.46%
94.4th percentile
In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. NOTE: this vulnerability exists because of an incomplete fix for S2-047 / CVE-2017-7672.
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa5.9MEDIUM
osv5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017
vendor_cisco·2017-09-07
CVE-2017-9793 [CRITICAL] CWE-20 Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017
Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017
On September 5, 2017, the Apache Software Foundation released security bulletins that disclosed three vulnerabilities in the Apache Struts 2 package. Of these vulnerabilities, the Apache Software Foundation classifies one as Critical Severity, one as Medium Severity, and one as Low Severity. For more information about the vulnerabilities, refer to the Details section of this advisory.
Multiple Cisco products incorporate a version of the Apache Struts 2 package that is affected by these vulnerabilities.
The following Snort rule can be used to detect possible exploitation of this vulnerability: Snort SIDs 44315 and 44327 through 44330.
This advisory is available at the following link:
https://sec.clouda
Red Hat
struts: A regular expression Denial of Service when using URLValidator
vendor_redhat·2017-09-05·CVSS 5.9
CVE-2017-9804 [MEDIUM] CWE-20 struts: A regular expression Denial of Service when using URLValidator
struts: A regular expression Denial of Service when using URLValidator
In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. NOTE: this vulnerability exists because of an incomplete fix for S2-047 / CVE-2017-7672.
Statement: A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in any Red Hat provided final products, and does not cause any vulnerability in the product, struts2-c
Cisco
Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017
vendor_cisco
CVE-2017-9804 Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017
CVE-2017-9804: Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017
On September 5, 2017, the Apache Software Foundation released security bulletins that disclosed three vulnerabilities in the Apache Struts 2 package. Of these vulnerabilities, the Apache Software Foundation classifies one as Critical Severity , one as Medium Severity , and one as Low Severity . For more information about the vulnerabilities, refer to the
CWE: CWE-20, CWE-399, CWE-20, CWE-399
Bug IDs: CSCvf86117, CSCvf86119, CSCvf86143, CSCvf86124, CSCvf86134
OSV
Apache Struts allows entering a custom URL in a form field if built-in URLValidator is used
osv·2018-10-16·CVSS 5.9
CVE-2017-9804 [MEDIUM] Apache Struts allows entering a custom URL in a form field if built-in URLValidator is used
Apache Struts allows entering a custom URL in a form field if built-in URLValidator is used
In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. NOTE: this vulnerability exists because of an incomplete fix for S2-047 / CVE-2017-7672.
GHSA
Apache Struts allows entering a custom URL in a form field if built-in URLValidator is used
ghsa·2018-10-16·CVSS 5.9
CVE-2017-9804 [MEDIUM] CWE-20 Apache Struts allows entering a custom URL in a form field if built-in URLValidator is used
Apache Struts allows entering a custom URL in a form field if built-in URLValidator is used
In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. NOTE: this vulnerability exists because of an incomplete fix for S2-047 / CVE-2017-7672.
No detection rules found.
No public exploits indexed.
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-003.txthttp://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.htmlhttp://www.securityfocus.com/bid/100612http://www.securitytracker.com/id/1039261https://security.netapp.com/advisory/ntap-20180629-0001/https://struts.apache.org/docs/s2-050.htmlhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170907-struts2http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-003.txthttp://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.htmlhttp://www.securityfocus.com/bid/100612http://www.securitytracker.com/id/1039261https://security.netapp.com/advisory/ntap-20180629-0001/https://struts.apache.org/docs/s2-050.htmlhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170907-struts2
2017-09-20
Published