The vendor explicitly states that these products are not affected by this CVE.
- google-guice-javadoc as a component of Red Hat Enterprise Linux 10
- google-guice.src as a component of Red Hat Enterprise Linux 10
- guice-assistedinject as a component of Red Hat Enterprise Linux 10
- guice-bom as a component of Red Hat Enterprise Linux 10
- guice-extensions as a component of Red Hat Enterprise Linux 10
- guice-grapher as a component of Red Hat Enterprise Linux 10
- guice-jmx as a component of Red Hat Enterprise Linux 10
- guice-jndi as a component of Red Hat Enterprise Linux 10
- guice-parent as a component of Red Hat Enterprise Linux 10
- guice-servlet as a component of Red Hat Enterprise Linux 10
- guice-throwingproviders as a component of Red Hat Enterprise Linux 10
- google-guice-javadoc (javapackages-tools:201801) as a component of Red Hat Enterprise Linux 8
- Summary
- A flaw was found in Apache Struts. An unauthenticated remote client can exploit a vulnerability where the framework's localized-text caches grow without bound. This occurs when no fixed locale is configured, and the locale for text lookups is derived from the incoming request. This can lead to the exhaustion of Java heap memory, resulting in a Denial of Service (DoS) for other users.
- Remediation
- No remediation text is recorded.
