CVE-2023-41835
published 2023-12-05CVE-2023-41835: When a Multipart request is performed but some of the fields exceed the maxStringLength limit, the upload files will remain in struts.multipart.saveDir even if…
PriorityP348high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
6.29%
92.8th percentile
When a Multipart request is performed but some of the fields exceed the maxStringLength limit, the upload files will remain in struts.multipart.saveDir even if the request has been denied.
Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 or Struts 6.3.0.1 or greater, which fixe this issue.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | struts | >= 2.0.0 < 2.5.32 | 2.5.32 |
| apache | struts | >= 6.1.2.1 < 6.3.0.1 | 6.3.0.1 |
| apache_software_foundation | apache_struts | 2.0.0 – 2.5.31 | — |
| apache_software_foundation | apache_struts | 6.1.2.1 – 6.3.0 | — |
| atlassian | confluence_data_center | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Atlassian
CVE-2023-41835: DoS (Denial of Service) org.apache.struts:struts2-core Dependency in Confluence Data Center and Serve r
vendor_atlassian·2024-02-20·CVSS 2.0
CVE-2023-41835 [HIGH] CVE-2023-41835: DoS (Denial of Service) org.apache.struts:struts2-core Dependency in Confluence Data Center and Serve r
CVE-2023-41835: DoS (Denial of Service) org.apache.struts:struts2-core Dependency in Confluence Data Center and Serve r
DoS (Denial of Service) org.apache.struts:struts2-core Dependency in Confluence Data Center and Serve r
CVE: CVE-2023-41835
Affected products: Confluence Data Center
Red Hat
struts: Excessive disk usage during file upload
vendor_redhat·2023-12-05·CVSS 7.5
CVE-2023-41835 [HIGH] CWE-913 struts: Excessive disk usage during file upload
struts: Excessive disk usage during file upload
When a Multipart request is performed but some of the fields exceed the maxStringLength limit, the upload files will remain in struts.multipart.saveDir even if the request has been denied.
Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 or Struts 6.3.0.1 or greater, which fixe this issue.
A flaw was found in struts. When a Multipart request is performed but some of the fields exceed the maxStringLength limit, the upload files will remain in 'struts.multipart.saveDir', even if the request has been denied.
Statement: This issue only affects Struts 2 and newer, which is not shipped in any Red Hat Products.
Package: org.apache.struts-struts-core (A-MQ Clients 2) - Not affected
Package: org.apache.struts-struts-core (Mig
OSV
Apache Struts Improper Control of Dynamically-Managed Code Resources vulnerability
osv·2023-12-05
CVE-2023-41835 [HIGH] Apache Struts Improper Control of Dynamically-Managed Code Resources vulnerability
Apache Struts Improper Control of Dynamically-Managed Code Resources vulnerability
When a Multipart request is performed but some of the fields exceed the maxStringLength limit, the upload files will remain in struts.multipart.saveDir even if the request has been denied.
Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 or Struts 6.3.0.1 or greater, which fix this issue.
GHSA
Apache Struts Improper Control of Dynamically-Managed Code Resources vulnerability
ghsa·2023-12-05
CVE-2023-41835 [HIGH] CWE-459 Apache Struts Improper Control of Dynamically-Managed Code Resources vulnerability
Apache Struts Improper Control of Dynamically-Managed Code Resources vulnerability
When a Multipart request is performed but some of the fields exceed the maxStringLength limit, the upload files will remain in struts.multipart.saveDir even if the request has been denied.
Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 or Struts 6.3.0.1 or greater, which fix this issue.
No detection rules found.
No public exploits indexed.
2023-12-05
Published