Red Hat Bugzilla – Bug 1561007
CVE-2018-1327 struts: Denial-of-Service attack via crafted XML request using Struts REST plugin
Last modified: 2018-03-27 08:38:15 EDT
The REST Plugin is using XStream library which is vulnerable and allow perform a DoS attack when using a malicious request with specially crafted XML payload. External References: https://cwiki.apache.org/confluence/display/WW/S2-056
Statement: This issue did not affect any of the Red Hat products as they did not include the Apache Struts 2 package.