Rapid7

vulnerability

Apache Struts: S2-065 (CVE-2023-41835): Security updates available for Apache Struts

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
Sep 14, 2023
Added
Sep 14, 2023
Modified
Mar 27, 2026

Description

When a Multipart request is performed but some of the fields exceed the maxStringLength  limit, the upload files will remain in struts.multipart.saveDir  even if the request has been denied.
Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 or Struts 6.3.0.1 or greater, which fixe this issue.

Solutions

apache-struts-upgrade-2_5_32apache-struts-upgrade-6_1_2_2apache-struts-upgrade-6_3_0_1
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.