If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Solution is to upgrade to Apache Struts version 2.5.12.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "2.5"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.5"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.8"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.10"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.10.1"
}
]
}