Bugzilla – Bug 1057268
VUL-0: CVE-2017-9793: struts: DoS attack via crafted XML payload prcoessed by REST Plugin using XStream library
Last modified: 2017-09-05 15:50:57 UTC
rh#1488481 References: https://bugzilla.redhat.com/show_bug.cgi?id=1488481 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-9793 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9793
The REST Plugin is using outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload. Affected versions: Struts 2.3.7 - Struts 2.3.33, Struts 2.5 - Struts 2.5.12 External References: https://struts.apache.org/docs/s2-051.html
we do not ship struts2.