CVE-2023-34396
published 2023-06-14CVE-2023-34396: Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: through…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
5.47%
91.9th percentile
Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: through 2.5.30, through 6.1.2.
Upgrade to Struts 2.5.31 or 6.1.2.1 or greater
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | struts | < 2.5.31 | 2.5.31 |
| apache | struts | >= 6.0.0 < 6.1.2.1 | 6.1.2.1 |
| apache_software_foundation | apache_struts | <= 2.5.30 | — |
| atlassian | bamboo_data_center | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_oracle7.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Atlassian
CVE-2023-34396: DoS (Denial of Service) apache-struts in Bamboo Data Center and Server
vendor_atlassian·2023-11-21·CVSS 7.5
CVE-2023-34396 [MEDIUM] CVE-2023-34396: DoS (Denial of Service) apache-struts in Bamboo Data Center and Server
CVE-2023-34396: DoS (Denial of Service) apache-struts in Bamboo Data Center and Server
DoS (Denial of Service) apache-struts in Bamboo Data Center and Server
CVE: CVE-2023-34396
Severity: HIGH
Affected products: Bamboo Data Center
Oracle
Oracle Oracle Communications Risk Matrix: CMP (Apache Struts) — CVE-2023-34396
vendor_oracle·2023-10-15·CVSS 7.5
CVE-2023-34396 [MEDIUM] Oracle Oracle Communications Risk Matrix: CMP (Apache Struts) — CVE-2023-34396
Oracle Oracle Communications Risk Matrix: CMP (Apache Struts) vulnerability
CVE: CVE-2023-34396
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
GHSA
Apache Struts vulnerable to memory exhaustion
ghsa·2023-06-14
CVE-2023-34396 [HIGH] CWE-770 Apache Struts vulnerable to memory exhaustion
Apache Struts vulnerable to memory exhaustion
Denial of service via out of memory (OOM) owing to no sanity limit on normal form fields in multipart forms. When a Multipart request has non-file normal form fields, Struts used to bring them into memory as Strings without checking their sizes. This could lead to an OOM if developer has set struts.multipart.maxSize to a value equal or greater than the available memory.
Upgrade to Struts 2.5.31 or 6.1.2.1 or greater
OSV
Apache Struts vulnerable to memory exhaustion
osv·2023-06-14
CVE-2023-34396 [HIGH] Apache Struts vulnerable to memory exhaustion
Apache Struts vulnerable to memory exhaustion
Denial of service via out of memory (OOM) owing to no sanity limit on normal form fields in multipart forms. When a Multipart request has non-file normal form fields, Struts used to bring them into memory as Strings without checking their sizes. This could lead to an OOM if developer has set struts.multipart.maxSize to a value equal or greater than the available memory.
Upgrade to Struts 2.5.31 or 6.1.2.1 or greater
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2023/06/14/3https://cwiki.apache.org/confluence/display/WW/S2-064https://security.netapp.com/advisory/ntap-20230706-0005/http://www.openwall.com/lists/oss-security/2023/06/14/3https://cwiki.apache.org/confluence/display/WW/S2-064https://security.netapp.com/advisory/ntap-20230706-0005/
2023-06-14
Published