Skip to main content

Improper Preservation of Permissions in org.apache.struts:struts2-assembly

CVE-2019-0233

  • org.apache.struts:struts2-assembly
  • org.apache.struts:struts2-core
  • org.apache.struts:struts2-parent
Severity High
Score 7.5/10

Summary

An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • HIGH

CWE-281 - Improper Preservation of Permissions

The software does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Advisory Timeline

  • Published