CVE-2019-0233: vulnerability in Apache Struts
Published · Updated
15Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 66%
exploitation probability
66%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Affected
1 product
Red Hat Enterprise Linux 5
no_fix_planned: Out of support scope
Not affected
4 products — because the vulnerable code is not present in the product
Red Hat JBoss Enterprise Application Platform 6 · Red Hat JBoss Fuse Service Works 6 · Red Hat JBoss Operations Network 3 · Red Hat OpenStack Platform 10 (Newton)
An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.
Affected products
n/a · Apache Struts