← back
CVE-2017-7672

CVE-2017-7672

EPSS 9.4%
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 9.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
13 Jul 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Solution is to upgrade to Apache Struts version 2.5.12.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →