Apache Struts Denial of Service Vulnerability (CVE-2018-1327)
Apache Struts Denial of Service Vulnerability (CVE-2018-1327)
Release date:
Updated on:
Affected Systems:
Apache Group Struts <2.5.16
Description:
Bugtraq id: 103516
CVE (CAN) ID: CVE-2018-1327
Struts2 is an extensible framework for building enterprise-level Jave Web applications.
In versions earlier than Apache Struts 2.5.16, the REST plug-in uses the XStream library, which is vulnerable to DoS attacks. Attackers exploit this vulnerability to cause denial-of-service (DoS) attacks by malicious requests.
<* Source: Alvaro Munoz
Yevgeniy Grushka
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://cwiki.apache.org/confluence/display/WW/S2-056
This article permanently updates link: https://www.bkjia.com/Linux/2018-03/151606.htm