CVE-2017-7672

Description

If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Solution is to upgrade to Apache Struts version 2.5.12.

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
1.818

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2017-9787,CVE-2017-7672 are fixed in Apache-struts2-core 2.5.12Windows
Vulnerabilities CVE-2017-9787,CVE-2017-7672 are fixed in Apache-structs2-core for Linux 2.5.12Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234