In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "2.5"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.3"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.4"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.5"
}
]
}