CVE-2017-9804 is a denial-of-service vulnerability affecting Apache Struts versions 2.3.7 through 2.3.33 and 2.5 through 2.5.12. It allows an attacker to overload the server process by submitting a specially crafted URL to a form field that uses the built-in URLValidator. This vulnerability carries a high CVSS score of 7.5, indicating a network-based attack with low complexity and high impact on availability. While there is no public exploit code available in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion and media coverage, suggesting awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.3.7CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.3.7:*:*:*:*:*:*:* | ||
2.3.8CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.3.8:*:*:*:*:*:*:* | ||
2.3.9CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.3.9:*:*:*:*:*:*:* | ||
2.3.10CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.3.10:*:*:*:*:*:*:* | ||
2.3.11CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.3.11:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.