NA

CVE-2023-41835

Published: 05/12/2023 Updated: 13/12/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

When a Multipart request is performed but some of the fields exceed the maxStringLength  limit, the upload files will remain in struts.multipart.saveDir  even if the request has been denied. Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 or Struts 6.3.0.1 or greater, which fixe this issue.

Vulnerable Product Search on Vulmon Subscribe to Product

apache struts

Vendor Advisories

Description<!---->A flaw was found in struts When a Multipart request is performed but some of the fields exceed the maxStringLength limit, the upload files will remain in 'strutsmultipartsaveDir', even if the request has been deniedA flaw was found in struts When a Multipart request is performed but some of the fields exceed the maxStringLeng ...