- Description
- Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-request parsing state could be shared across concurrent requests, allowing data associated with one request to become observable in another, and configured parsing limits not to be enforced as intended. Populating actions from a JSON request body is not enabled by default; applications that do not use the JSON plugin are not affected. This issue affects Apache Struts: 7.2.1. Users are recommended to upgrade to version 7.3.0, which fixes the issue.
- Source
- security@apache.org
- NVD status
- Analyzed
- Products
- struts
CVSS 3.1
- Type
- Secondary
- Base score
- 4.3
- Impact score
- 1.4
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity
- MEDIUM
- security@apache.org
- CWE-567
- Hype score
- Not currently trending
Apache Strutsの脆弱性(Moderate: CVE-2026-73631, CVE-2026-73633, CVE-2026-73634, CVE-2026-73635, Low: CVE-2026-73632) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #apache #struts #dos https://t.co/8XUCJQetCY
@omokazuki
14 Aug 2026
125 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
Apache Strutsで5件の脆弱性(S2-070~S2-074) CVE-2026-73631 CVE-2026-73632 CVE-2026-73633 CVE-2026-73634 CVE-2026-73635 https://t.co/M7OFPs9BmA
@autumn_good_35
14 Aug 2026
617 Impressions
2 Retweets
3 Likes
1 Bookmark
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:struts:7.2.1:*:*:*:*:*:*:*",
"matchCriteriaId": "5B413DED-A87F-4793-A0DC-7D11B1C7A6BE",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]