CVE-2016-8738

All FrameworksApache StrutsCWE-OtherCVE-2016-8738

CVE-2016-8738

State: PUBLISHED · Published: 2017-09-20 · Updated: 2024-09-16 · Assigner: apache
Description
In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2016/8xxx/CVE-2016-8738.json