cbcvebase.
CVE-2023-41835
published 2023-12-05

CVE-2023-41835: When a Multipart request is performed but some of the fields exceed the maxStringLength limit, the upload files will remain in struts.multipart.saveDir even if…

PriorityP348high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
6.29%
92.8th percentile
When a Multipart request is performed but some of the fields exceed the maxStringLength limit, the upload files will remain in struts.multipart.saveDir even if the request has been denied. Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 or Struts 6.3.0.1 or greater, which fixe this issue.

Affected

5 ranges
VendorProductVersion rangeFixed in
apachestruts>= 2.0.0 < 2.5.322.5.32
apachestruts>= 6.1.2.1 < 6.3.0.16.3.0.1
apache_software_foundationapache_struts2.0.0 – 2.5.31
apache_software_foundationapache_struts6.1.2.1 – 6.3.0
atlassianconfluence_data_center

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.