The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted XML payload.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "2.3.7"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.8"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.9"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.10"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.11"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.12"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.13"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.14"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.14.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.14.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.14.3"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.15"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.15.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.15.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.15.3"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.16"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.16.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.16.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.16.3"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.17"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.19"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.20"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.20.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.20.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.21"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.22"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.23"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.24.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.24.3"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.25"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.26"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.27"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.28"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.28.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.29"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.30"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.31"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.32"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.33"
},
{
"introduced": "0"
},
{
"last_affected": "2.5"
},
{
"introduced": "0"
},
{
"last_affected": "2.5-beta1"
},
{
"introduced": "0"
},
{
"last_affected": "2.5-beta2"
},
{
"introduced": "0"
},
{
"last_affected": "2.5-beta3"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.3"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.4"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.5"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.6"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.7"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.8"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.9"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.10"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.10.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.12"
}
]
}