The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.apache.struts:struts2-rest-plugin(Maven) | 0 | 2.3.34 | N/A |
| org.apache.struts:struts2-rest-plugin(Maven) | 2.5.0 | 2.5.13 | N/A |
CVSS Metrics