Red Hat Bugzilla – Bug 1488481
CVE-2017-9793 struts: DoS attack via crafted XML payload processed by REST Plugin using XStream library
Last modified: 2017-09-06 09:37:18 EDT
The REST Plugin is using outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload. Affected versions: Struts 2.3.7 - Struts 2.3.33, Struts 2.5 - Struts 2.5.12 External References: https://struts.apache.org/docs/s2-051.html
Created struts tracking bugs for this issue: Affects: epel-7 [bug 1488487] Affects: fedora-all [bug 1488488]
Statement: This issue did not affect any of the Red Hat products as they did not include the Apache Struts 2 package.