CVE-2017-7672 is a denial-of-service vulnerability affecting Apache Struts versions prior to 2.5.12. An attacker can craft a special URL that, when processed by the built-in URLValidator, overloads the server process. This medium-severity vulnerability (CVSS 5.9) has a network attack vector and high impact on availability, but high attack complexity. While Oracle released patches, there is no public exploit code (Metasploit, Nuclei, ExploitDB) and minimal community discussion, indicating low active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.5CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.5:*:*:*:*:*:*:* | ||
2.5.1CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.5.1:*:*:*:*:*:*:* | ||
2.5.2CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.5.2:*:*:*:*:*:*:* | ||
2.5.5CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.5.5:*:*:*:*:*:*:* | ||
2.5.8CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.5.8:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.