Apache Struts 中存在并发执行时使用共享资源且同步不当(竞态条件)漏洞。当本地化消息格式化日期或时间参数时,应用程序范围内文本提供程序为该消息保留的格式化器会被并发处理的请求共享,缺乏隔离性,导致一个用户的值可能出现在另一个用户的响应中,或者渲染失败并表现为服务器错误。未本地化消息格式化日期或时间参数的应用不受此漏洞影响。 此漏洞影响以下 Apache Struts 版本: 2.0.0 至 2.3.37 2.5.0 至 2.5.33 6.0.0 至 6.11.0 7.0.0 至 7.3.0 建议用户升级
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Struts | 2.0.0≤ 2.3.37 |
affected |
2.5.0≤ 2.5.33 |
affected | ||
6.0.0≤ 6.11.0 |
affected | ||
7.0.0≤ 7.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Struts | 2.0.0 ~ 2.3.37 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104713 | Apache Struts: Unbounded request body read in the REST plugin | |
| CVE-2026-104712 | Apache Struts: Disproportionate response size when rendering BigDecimal request parameters | |
| CVE-2026-104711 | Apache Struts: OGNL injection in the legacy RESTful action mapper |
No comments yet