CVE-2023-34396 is a high-severity "Allocation of Resources Without Limits or Throttling" vulnerability affecting Apache Struts versions through 2.5.30 and through 6.1.2. This flaw allows an unauthenticated attacker to remotely cause a denial of service by exhausting system resources, as indicated by its CVSS score of 7.5 (AV:N/AC:L/A:H). While no public exploit code or active exploitation has been observed, and community discussion is minimal, organizations should upgrade to Struts 2.5.31 or 6.1.2.1 or greater to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.5.31CPE matchmatch criteria | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.1.2.1CPE matchmatch criteria | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* | ||
>= 0, <= 2.5.30CPE match | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* | ||
>= 0, <= 6.1.2CPE match | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.