[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    [oss-security] S2-063: CVE-2023-34149: Apache Struts: DoS via OOM owing to not properly checking of 
From:       Yasser Zamani <yasserzamani () apache ! org>
Date:       2023-06-14 7:34:50
Message-ID: 55e6c435-1cad-505b-e8b2-632e801a19f0 () apache ! org
[Download RAW message or body]

Affected versions:

- Apache Struts through 2.5.30
- Apache Struts through 6.1.2

Description:

Allocation of Resources Without Limits or Throttling vulnerability in Apache Software \
Foundation Apache Struts.This issue affects Apache Struts: through 2.5.30, through 6.1.2.

Credit:

Matthew McClain (finder)

References:

https://cwiki.apache.org/confluence/display/WW/S2-063
https://struts.apache.org/
https://www.cve.org/CVERecord?id=CVE-2023-34149


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic