VYPR
High severity7.5NVD Advisory· Published Mar 27, 2018· Updated Jun 17, 2026

CVE-2018-1327

CVE-2018-1327

Description

The Apache Struts REST Plugin is using XStream library which is vulnerable and allow perform a DoS attack when using a malicious request with specially crafted XML payload. Upgrade to the Apache Struts version 2.5.16 and switch to an optional Jackson XML handler as described here http://struts.apache.org/plugins/rest/#custom-contenttypehandlers. Another option is to implement a custom XML handler based on the Jackson XML handler from the Apache Struts 2.5.16.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.struts:struts2-rest-pluginMaven
>= 2.1.1, < 2.5.162.5.16

Affected products

2

Patches

Vulnerability mechanics

References

17

News mentions

0

No linked articles in our index yet.