V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2023-41835
DEB
High

When a Multipart request is performed but some of the fields exceed the maxStringLength limit, the upload files will remain in struts.multi…

CVSS
7.5
High
EPSS
0.06
p92
Published
2023-01-01
Updated
2023-01-01
Description

When a Multipart request is performed but some of the fields exceed the maxStringLength  limit, the upload files will remain in struts.multipart.saveDir  even if the request has been denied. Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 or Struts 6.3.0.1 or greater, which fixe this issue.

Tags · CWE
Pre-auth
CWE-400
CWE-459
CWE-913
CAPEC-147
CAPEC-227
CAPEC-492
Affected products
Struts 2.0.0–2.5.32Struts 6.1.2.1–6.3.0.1
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Timeline
2023-01-01
Published
2023-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.063 · p92
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-227 · CWE-400
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
libstruts1.2-javaTracked
libstruts1.2-javaTracked
libstruts1.2-javaTracked
libstruts1.2-javaTracked
struts*Tracked
Source databases
DEB
CVE
UBU
Related vulnerabilities