Ce mail provient de l'extérieur, restons vigilants ===================================================================== CERT-Renater Note d'Information No. 2025/VULN842 _____________________________________________________________________ DATE : 11/12/2025 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Apache Struts versions prior to 6.8.0, 7.1.1. ===================================================================== https://lists.apache.org/thread/b83ql12tb8ro5l8xh1z7sto5vsxs04z8 _____________________________________________________________________ CVE-2025-66675: Apache Struts: File leak in multipart request processing causes disk exhaustion (DoS) - version ranges fixed Severity: important Affected versions: - Apache Struts (org.apache.struts:struts2-core) 2.0.0 through 6.7.* - Apache Struts (org.apache.struts:struts2-core) 7.0.0 through 7.0.* Description: Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.4, from 7.0.0 through 7.0.3. Users are recommended to upgrade to version 6.8.0 or 7.1.1, which fixes the issue. It's related to https://cve.org/CVERecord?id=CVE-2025-64775 - this CVE addresses missing affected version 6.7.4 Credit: Nicolas Fournier (reporter) References: https://cwiki.apache.org/confluence/display/WW/S2-068 https://cve.org/CVERecord?id=CVE-2025-64775 https://cve.org/CVERecord?id=CVE-2025-66675 https://struts.apache.org/ Kind regards Łukasz ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================