logo

Database

Asymmetric denial of service In org.apache.struts:struts2-core

Description

Spring AOP functionality (Struts) vulnerable to DoS attack When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack. Solution is to upgrade to Apache Struts version 2.5.12 or 2.3.33.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions