CVE-2023-34149
published 2023-06-14CVE-2023-34149: Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: through…
PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
5.40%
91.8th percentile
Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: through 2.5.30, through 6.1.2.
Upgrade to Struts 2.5.31 or 6.1.2.1 or greater.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | struts | < 2.5.31 | 2.5.31 |
| apache | struts | >= 6.0.0 < 6.1.2.1 | 6.1.2.1 |
| apache_software_foundation | apache_struts | <= 2.5.30 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Struts vulnerable to memory exhaustion
osv·2023-06-14
CVE-2023-34149 [MEDIUM] Apache Struts vulnerable to memory exhaustion
Apache Struts vulnerable to memory exhaustion
Denial of service via out of memory (OOM) owing to not properly checking of list bounds. When a Multipart request has non-file normal form fields, Struts used to bring them into memory as Strings without checking their sizes. This could lead to OOM if developer has set struts.multipart.maxSize to a value equal or greater than the available memory.
Upgrade to Struts 2.5.31 or 6.1.2.1 or greater.
GHSA
Apache Struts vulnerable to memory exhaustion
ghsa·2023-06-14
CVE-2023-34149 [MEDIUM] CWE-770 Apache Struts vulnerable to memory exhaustion
Apache Struts vulnerable to memory exhaustion
Denial of service via out of memory (OOM) owing to not properly checking of list bounds. When a Multipart request has non-file normal form fields, Struts used to bring them into memory as Strings without checking their sizes. This could lead to OOM if developer has set struts.multipart.maxSize to a value equal or greater than the available memory.
Upgrade to Struts 2.5.31 or 6.1.2.1 or greater.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2023/06/14/2https://cwiki.apache.org/confluence/display/WW/S2-063https://security.netapp.com/advisory/ntap-20230706-0005/http://www.openwall.com/lists/oss-security/2023/06/14/2https://cwiki.apache.org/confluence/display/WW/S2-063https://security.netapp.com/advisory/ntap-20230706-0005/
2023-06-14
Published