CVE-2017-9793

All FrameworksApache StrutsCWE-OtherCVE-2017-9793

CVE-2017-9793

State: PUBLISHED · Published: 2017-09-20 · Updated: 2024-09-16 · Assigner: apache
Description
The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2017/9xxx/CVE-2017-9793.json