{"id":"GHSA-xcrm-qpp8-hcw4","summary":"Moderate severity vulnerability that affects org.apache.struts:struts2-rest-plugin","details":"In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.","aliases":["CVE-2017-15707"],"modified":"2024-02-17T05:28:31.799954Z","published":"2018-10-16T19:35:55Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-06-16T22:02:58Z","nvd_published_at":null,"cwe_ids":["CWE-20"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-15707"},{"type":"WEB","url":"https://cwiki.apache.org/confluence/display/WW/S2-054"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-xcrm-qpp8-hcw4"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20171214-0001"},{"type":"WEB","url":"http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html"},{"type":"WEB","url":"http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/102021"},{"type":"WEB","url":"http://www.securitytracker.com/id/1039946"}],"affected":[{"package":{"name":"org.apache.struts:struts2-rest-plugin","ecosystem":"Maven","purl":"pkg:maven/org.apache.struts/struts2-rest-plugin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.5.0"},{"fixed":"2.5.16"}]}],"versions":["2.5","2.5.1","2.5.10","2.5.10.1","2.5.12","2.5.13","2.5.14","2.5.14.1","2.5.2","2.5.5","2.5.8"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.5.14","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-xcrm-qpp8-hcw4/GHSA-xcrm-qpp8-hcw4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}