Back

HIGH

Apache Struts: DoS via OOM owing to no sanity limit on normal form fields in multipart forms

Published Jun 14, 2023

Description

Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: through 2.5.30, through 6.1.2.

Upgrade to Struts 2.5.31 or 6.1.2.1 or greater

Affected products

Remediation

No remediation recorded yet.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Jun 14, 2023
Updated Feb 13, 2025
Reserved Jun 4, 2023
CISA Vulnrichment
Updated Oct 9, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-4G42-GQRG-4633