CVE-2025-68493 describes a critical Missing XML Validation vulnerability in Apache Struts versions 2.0.0 through 6.1.0, allowing for remote code execution and denial of service. With a CVSS score of 8.1 (HIGH), this vulnerability is easily exploitable over the network without authentication, potentially leading to complete compromise of confidentiality and availability. While no active exploits, Metasploit modules, or public exploit code are currently known, the high FAUCET Risk Score of 87/100 indicates its significant potential impact. Users are strongly advised to upgrade to Apache Struts version 6.1.1 to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, <= 2.3.37CPE matchmatch criteria | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* | ||
>= 2.5.0, <= 2.5.33CPE matchmatch criteria | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.1.1CPE matchmatch criteria | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* | ||
>= 2.0.0, < 2.2.1CPE match | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* | ||
>= 2.2.1, <= 6.1.0CPE match | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.