Total vulnerabilities in the database
The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a null value for a URL field.
Software | From | Fixed in |
---|---|---|
apache / struts | 2.3.28 | 2.3.28.x |
apache / struts | 2.5-beta2 | 2.5-beta2.x |
apache / struts | 2.5-beta3 | 2.5-beta3.x |
apache / struts | 2.3.24.1 | 2.3.24.1.x |
apache / struts | 2.5-beta1 | 2.5-beta1.x |
apache / struts | 2.3.24.3 | 2.3.24.3.x |
apache / struts | 2.3.20.1 | 2.3.20.1.x |
apache / struts | 2.3.24 | 2.3.24.x |
apache / struts | 2.3.28.1 | 2.3.28.1.x |
apache / struts | 2.3.20.3 | 2.3.20.3.x |
apache / struts | 2.5 | 2.5.x |
apache / struts | 2.3.20 | 2.3.20.x |
![]() |
2.3.20 | 2.3.29 |
![]() |
2.5.0 | 2.5.13 |