struts2: access permission override when performing a file upload leads to DoS
Published Sep 14, 2020
7.5
HIGHCVSS 3.1
EPSS 66.15%
Description
An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.
Affected products
- Vendor n/a Product Apache Struts Defaultn/a
- Version Apache Struts 2.0.0 to 2.5.20StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Apache Struts | n/a |
|
Configuration 2
- 12.5.0
- 8.0.3
- 8.0.6
- 8.0.6
- ≤ 8.0.23
No data.
Red Hat Enterprise Linux 5
struts
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
struts
Not affected
Red Hat JBoss Fuse Service Works 6
struts
Not affected
Red Hat JBoss Operations Network 3
struts
Not affected
Red Hat OpenStack Platform 10 (Newton)
opendaylight
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | struts | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | struts | Not affected | n/a |
| Red Hat JBoss Fuse Service Works 6 | struts | Not affected | n/a |
| Red Hat JBoss Operations Network 3 | struts | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | opendaylight | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (33 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 66.15% (0.66146) | 99.26th | v5 (v2026.06.15) |
| Oct 2, 2026 | 66.15% (0.66146) | 99.26th | v5 (v2026.06.15) |
| Oct 1, 2026 | 68.05% (0.68050) | 99.31th | v5 (v2026.06.15) |
| Jul 3, 2026 | 68.76% (0.68761) | 99.26th | v5 (v2026.06.15) |
| Jun 15, 2026 | 70.08% (0.70082) | 99.29th | v5 (v2026.06.15) |
| Mar 4, 2026 | 7.78% (0.07780) | 91.80th | v4 (v2025.03.14) |
| Dec 8, 2025 | 9.31% (0.09311) | 92.45th | v4 (v2025.03.14) |
| Nov 21, 2025 | 7.78% (0.07780) | 91.59th | v4 (v2025.03.14) |
| Nov 18, 2025 | 37.62% (0.37619) | 97.01th | v4 (v2025.03.14) |
| Jul 9, 2025 | 6.86% (0.06858) | 90.91th | v4 (v2025.03.14) |
| Jun 22, 2025 | 4.73% (0.04734) | 88.92th | v4 (v2025.03.14) |
| Jun 20, 2025 | 6.86% (0.06858) | 90.89th | v4 (v2025.03.14) |
| Mar 30, 2025 | 4.73% (0.04734) | 88.39th | v4 (v2025.03.14) |
| Mar 29, 2025 | 73.93% (0.73932) | 98.46th | v4 (v2025.03.14) |
| Mar 24, 2025 | 4.73% (0.04734) | 88.37th | v4 (v2025.03.14) |
| Mar 23, 2025 | 51.42% (0.51419) | 97.56th | v4 (v2025.03.14) |
| Mar 17, 2025 | 4.73% (0.04734) | 88.68th | v4 (v2025.03.14) |
| Dec 17, 2024 | 15.60% (0.15603) | 95.88th | v3 (v2023.03.01) |
| Aug 5, 2024 | 9.79% (0.09793) | 94.84th | v3 (v2023.03.01) |
| Jul 19, 2024 | 13.15% (0.13147) | 95.58th | v3 (v2023.03.01) |
| May 31, 2023 | 13.22% (0.13219) | 94.70th | v3 (v2023.03.01) |
| Apr 21, 2023 | 12.37% (0.12368) | 94.55th | v3 (v2023.03.01) |
| Mar 7, 2023 | 16.11% (0.16113) | 95.06th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.90% (0.01900) | 77.41th | v2 (v2022.01.01) |
| Mar 5, 2023 | 1.90% (0.01900) | 77.41th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.90% (0.01900) | 75.41th | v2 (v2022.01.01) |
| Feb 4, 2022 | 12.71% (0.12706) | 90.03th | v2 (v2022.01.01) |
| Feb 3, 2022 | 17.53% (0.17530) | 90.86th | v1 |
| Jan 6, 2022 | 17.53% (0.17530) | 90.75th | v1 |
| Oct 21, 2021 | 4.52% (0.04523) | 84.55th | v1 |
| Sep 1, 2021 | 3.79% (0.03793) | 82.89th | v1 |
| Jun 15, 2021 | 3.79% (0.03793) | 0.00th | v1 |
| Apr 14, 2021 | 3.05% (0.03053) | 0.00th | v1 |
References (10)
- https://access.redhat.com/security/cve/CVE-2019-0233 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1869682 Issue Tracking
- https://cwiki.apache.org/confluence/display/ww/s2-060 x_refsource_MISCVendor Advisory
- https://github.com/advisories/GHSA-ccp5-gg58-pxfm Advisory
- https://launchpad.support.sap.com/#/notes/2982840 x_refsource_MISCPermissions RequiredThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-0233
- https://www.cve.org/CVERecord?id=CVE-2019-0233
- https://www.oracle.com/security-alerts/cpuApr2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html x_refsource_MISCPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-0233 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1869682 | Issue Tracking | |
| https://cwiki.apache.org/confluence/display/ww/s2-060 | x_refsource_MISCVendor Advisory | |
| https://github.com/advisories/GHSA-ccp5-gg58-pxfm | Advisory | |
| https://launchpad.support.sap.com/#/notes/2982840 | x_refsource_MISCPermissions RequiredThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-0233 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-0233 | ||
| https://www.oracle.com/security-alerts/cpuApr2021.html | x_refsource_MISCPatchThird Party Advisory | |
| https://www.oracle.com/security-alerts/cpujan2021.html | x_refsource_MISCPatchThird Party Advisory | |
| https://www.oracle.com/security-alerts/cpuoct2021.html | x_refsource_MISCPatchThird Party Advisory |
Change history (0)
No recorded changes yet.