CVE-2023-41835

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/12/2023
Last modified:
04/11/2025

Description

When a Multipart request is performed but some of the fields exceed the maxStringLength  limit, the upload files will remain in struts.multipart.saveDir  even if the request has been denied.<br /> Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 or Struts 6.3.0.1 or greater, which fixe this issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* 2.0.0 (including) 2.5.32 (excluding)
cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* 6.1.2.1 (including) 6.3.0.1 (excluding)