A serious vulnerability has been identified in Apache Struts 2, an open-source web framework, exposing many businesses to significant cybersecurity risks.

The vulnerability, which carries the code CVE-2023-50164, allows hackers to exploit file upload functions, leading to unauthorized access and possible remote code execution (RCE).
Read also: TellYouThePass ransomware: Added to Apache ActiveMQ RCE attacks
The issue affects Apache Struts 2 versions 2.0.0 to 2.3.37 (which have been retired), 2.5.0 to 2.5.32, and 6.0.0 to 6.3.0. With a CVSS score of 9.8, the vulnerability poses a critical risk to organizations using the affected versions.
The vulnerability stems from the handling of file uploads in Apache Struts 2. Attackers can upload malicious files to the server, gaining complete control over the system. They also use case-sensitive HTTP parameters to bypass standard security measures.
The implications of this vulnerability are serious, including remote code execution, unauthorized access to sensitive data, system compromise, and potential use as a base for further network attacks.
See also: Vulnerability in Apache Tomcat allows Dos attacks
Apache Struts has already released updates that address the vulnerability. It is recommended that you upgrade immediately to Apache Struts 2.5.33 or Apache Struts 6.3.0.2 and later. Since there are no known workarounds for the vulnerability, upgrading is essential to ensure protection.

Additionally, organizations using Apache Struts 2 should take additional security measures: restrict file upload settings, implement modern firewalls (WAFs), frequently update their software, and actively monitor for suspicious activity. Prompt action is critical to protecting systems and maintaining security in an environment of growing cyber threats.
Read more: Apache Roller CSRF vulnerability allows privilege escalation
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
