Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-41835


When a Multipart request is performed but some of the fields exceed the maxStringLength  limit, the upload files will remain in struts.multipart.saveDir  even if the request has been denied. Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 or Struts 6.3.0.1 or greater, which fixe this issue.


Published

2023-12-05T09:15:07.093

Last Modified

2025-05-28T16:15:30.367

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-459
  • Type: Primary
    CWE-459

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache struts < 2.5.32 Yes
Application apache struts < 6.3.0.1 Yes

References