In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
{
"github_reviewed": true,
"nvd_published_at": null,
"github_reviewed_at": "2020-06-16T22:02:58Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-20"
]
}