Loading HuntDB...

GHSA-x5x7-3v85-wpc4

GitHub Security Advisory

Apache Struts allows entering a custom URL in a form field if built-in URLValidator is used

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. NOTE: this vulnerability exists because of an incomplete fix for S2-047 / CVE-2017-7672.

Affected Packages

Maven org.apache.struts:struts2-core
Affected versions: 2.3.7 (fixed in 2.3.34)
Maven org.apache.struts:struts2-core
Affected versions: 2.5.0 (fixed in 2.5.13)

Related CVEs

Key Information

GHSA ID
GHSA-x5x7-3v85-wpc4
Published
October 16, 2018 7:37 PM
Last Modified
January 4, 2024 11:26 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.apache.struts:struts2-core
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 28, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.