Red Hat Bugzilla – Bug 1348253
CVE-2016-4465 struts: Possible DoS attack when using URLValidator
Last modified: 2018-01-30 10:45:08 EST
If an application allows enter na URL field in a form and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Affected versions: Struts 2.3.20 - Struts 2.3.28.1 and Struts 2.5 External References: https://struts.apache.org/docs/s2-041.html
thanks for the information, but I remove from the CC list.