Apache Struts 2 OGNL Cache Poisoning Denial of Service Vulnerability (CVE-2016-3093)
Apache Struts 2 OGNL Cache Poisoning Denial of Service Vulnerability (CVE-2016-3093)
Release date:
Updated on:
Affected Systems:
Apache Group Struts 2.0.0-2.3.24.1
Description:
CVE (CAN) ID: CVE-2016-3093
Struts2 is an extensible framework for building enterprise-level Jave Web applications.
In Struts 2.0.0-Struts 2.3.24.1, The OGNL expression language does not properly store the cache referenced by the method, which can cause DoS attacks.
<* Source: Tao Wang
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://struts.apache.org/docs/s2-034.html
Https://struts.apache.org/docs/version-notes-23203.html
Https://struts.apache.org/docs/version-notes-23243.html
Https://struts.apache.org/docs/version-notes-2328.html
This article permanently updates the link address: