← Back

CVE-2023-41835

nvd nist
Published: Dec 5, 2023Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

When a Multipart request is performed but some of the fields exceed the maxStringLength  limit, the upload files will remain in struts.multipart.saveDir  even if the request has been denied. Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 or Struts 6.3.0.1 or greater, which fixe this issue.

Affected (2)

Products: Apache: Struts
1 product
Struts
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 2.0.0 to 2.5.32
From 6.1.2.1 to 6.3.0.1

References (5)

Source: security@apache.org
Mailing ListRelease Notes
Source: security@apache.org
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory

Timeline

No history available yet.