Spring AOP functionality (Struts) vulnerable to DoS attack
High severity
GitHub Reviewed
Published
Oct 16, 2018
to the GitHub Advisory Database
•
Updated Jan 4, 2024
Package
Affected versions
>= 2.5.0, < 2.5.12
>= 2.3.7, < 2.3.33
Patched versions
2.5.12
2.3.33
Description
Published to the GitHub Advisory Database
Oct 16, 2018
Reviewed
Jun 16, 2020
Last updated
Jan 4, 2024
When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack. Solution is to upgrade to Apache Struts version 2.5.12 or 2.3.33.
References