CVE-2025-68493: CWE-611 Improper Restriction of XML External Entity Reference in Apache Software Foundation Apache Struts
Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.
AI Analysis
Technical Summary
This vulnerability (CVE-2025-68493) in Apache Struts is classified under CWE-611 (Improper Restriction of XML External Entity Reference). It arises from missing XML validation in affected versions, enabling malicious XML input to exploit external entity processing. The affected versions include all releases from 2.0.0 through 6.1.0. The vulnerability has a CVSS 3.1 base score of 8.1, indicating high severity, with network attack vector, low attack complexity, no privileges required, user interaction required, unchanged scope, high confidentiality impact, no integrity impact, and high availability impact. The vendor advisory from Red Hat confirms the issue and recommends upgrading to Apache Struts 6.1.1 to remediate the vulnerability.
Potential Impact
Successful exploitation can lead to high confidentiality impact (disclosure of sensitive information) and high availability impact (denial of service). The vulnerability does not affect integrity. The attack can be performed remotely without privileges but requires user interaction. This can result in significant disruption and data exposure in affected Apache Struts deployments.
Mitigation Recommendations
A fix is available in Apache Struts version 6.1.1. Users should upgrade to this version to remediate the vulnerability. The vendor advisory from Red Hat confirms this remediation approach. No additional mitigation steps are specified or required beyond applying the official update.
CVE-2025-68493: CWE-611 Improper Restriction of XML External Entity Reference in Apache Software Foundation Apache Struts
Description
Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.
CVSS v3.1
Score 8.1high
Affected software
pkg:maven/org.apache.struts/struts2-coreRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2025-68493) in Apache Struts is classified under CWE-611 (Improper Restriction of XML External Entity Reference). It arises from missing XML validation in affected versions, enabling malicious XML input to exploit external entity processing. The affected versions include all releases from 2.0.0 through 6.1.0. The vulnerability has a CVSS 3.1 base score of 8.1, indicating high severity, with network attack vector, low attack complexity, no privileges required, user interaction required, unchanged scope, high confidentiality impact, no integrity impact, and high availability impact. The vendor advisory from Red Hat confirms the issue and recommends upgrading to Apache Struts 6.1.1 to remediate the vulnerability.
Potential Impact
Successful exploitation can lead to high confidentiality impact (disclosure of sensitive information) and high availability impact (denial of service). The vulnerability does not affect integrity. The attack can be performed remotely without privileges but requires user interaction. This can result in significant disruption and data exposure in affected Apache Struts deployments.
Mitigation Recommendations
A fix is available in Apache Struts version 6.1.1. Users should upgrade to this version to remediate the vulnerability. The vendor advisory from Red Hat confirms this remediation approach. No additional mitigation steps are specified or required beyond applying the official update.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2025-12-19T06:50:08.538Z
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2025-68493","vendor":"Red Hat"}]
Threat ID: 696406d1da2266e838e19a2c
Added to database: 01/11/2026, 20:23:45 UTC
Last enriched: 07/15/2026, 08:22:30 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 1741
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.