When a Multipart request is performed but some of the fields exceed the maxStringLength  limit, the upload files will remain in struts.multipart.saveDir  even if the request has been denied. Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 or Struts 6.3.0.1 or greater, which fixe this issue.
History

Wed, 28 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2023-12-05T08:37:31.602Z

Updated: 2025-05-28T15:56:00.942Z

Reserved: 2023-09-04T07:53:19.551Z

Link: CVE-2023-41835

cve-icon Vulnrichment

Updated: 2024-08-02T19:09:48.717Z

cve-icon NVD

Status : Modified

Published: 2023-12-05T09:15:07.093

Modified: 2025-05-28T16:15:30.367

Link: CVE-2023-41835

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-12-05T00:00:00Z

Links: CVE-2023-41835 - Bugzilla