CVE-2023-34149: Apache Struts: DoS via OOM owing to not properly checking of list bounds
Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: through 2.5.30, through 6.1.2.
Upgrade to Struts 2.5.31 or 6.1.2.1 or greater.
Other sources
Apache Struts is vulnerable to a denial of service, caused by a flaw with only handling setProperty() but not getProperty(). By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Strutsto a version that resolves this vulnerability.Fixed in 2.5.31 - Upgrade
Upgrade
Apache Strutsto a version that resolves this vulnerability.Fixed in 6.1.2.1
Event History
Frequently Asked Questions
What is CVE-2023-34149?
CVE-2023-34149 is a vulnerability in Apache Struts that can be exploited by a remote attacker to cause a denial of service condition.
What software is affected by CVE-2023-34149?
IBM QRadar SIEM version 7.5.0 - 7.5.0 UP6 is affected by CVE-2023-34149.
How does CVE-2023-34149 work?
CVE-2023-34149 is caused by a flaw in Apache Struts where it only handles setProperty() but not getProperty(). By sending a specially crafted request, a remote attacker can exploit this vulnerability.
What is the severity of CVE-2023-34149?
CVE-2023-34149 has a severity value of 7.5, which is considered high.
How can CVE-2023-34149 be fixed?
To fix CVE-2023-34149, it is recommended to update to a version of Apache Struts that handles both setProperty() and getProperty() properly.