Red Hat Bugzilla – Bug 1488491
CVE-2017-9804 struts: A regular expression Denial of Service when using URLValidator
Last modified: 2017-09-05 10:06:12 EDT
The previous fix issued with S2-047 (CVE-2017-7672) was incomplete. If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Affected versions: Struts 2.3.7 - Struts 2.3.33, Struts 2.5 - Struts 2.5.12 External References: https://struts.apache.org/docs/s2-050.html