CVE-2016-4465

MEDIUM5.3EPSS 10.4%

Apache Struts vulnerable to possible DoS attack when using URLValidator

Published: 5/17/2022Modified: 2/16/2024

Description

The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.13 allows remote attackers to cause a denial of service via a null value for a URL field.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.3CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References (9)