[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Apache Struts2 S2-055 DoS Vulnerability

Author
David Dillard
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-29102
Category
dos / poc
Date add
02-12-2017
CVE
CVE-2017-7525
Platform
multiple
Summary

Vulnerability in the Jackson JSON library
	
Who should read this 	All Struts 2 developers and users which are using the REST plugin
Impact of vulnerability 	Not clear, please read the linked issue for more details. https://github.com/FasterXML/jackson-databind/issues/1599
Maximum security rating 	Medium
Recommendation 	Upgrade to Struts 2.5.14.1
Affected Software 	Struts 2.5 - Struts 2.5.14
Reporter 	David Dillard < david dot dillard at veritas dot com> - Veritas Technologies Product Security Group
CVE Identifier 	CVE-2017-7525
Problem

A vulnerability was detected in the latest Jackson JSON library, which was reported here. Upgrade com.fasterxml.jackson to version 2.9.2 to address CVE-2017-7525.
Solution

Upgrade to Apache Struts version 2.5.14.1. Another solution is to manually upgrade Jackson dependencies in your project to not vulnerable versions, see this comment.
Backward compatibility

No backward incompatibility issues are expected.
Workaround

Upgrade Jackson JSON library to the latest version.

Source
https://cwiki.apache.org/confluence/display/WW/s2-055

#  0day.today [2024-11-04]  #