HomeSecurityRCE vulnerability in Apache Struts 2 puts servers at risk

RCE vulnerability in Apache Struts 2 puts servers at risk

A serious vulnerability has been identified in Apache Struts 2, an open-source web framework, exposing many businesses to significant cybersecurity risks.

Apache Struts 2

The vulnerability, which carries the code CVE-2023-50164, allows hackers to exploit file upload functions, leading to unauthorized access and possible remote code execution (RCE).

Read also: TellYouThePass ransomware: Added to Apache ActiveMQ RCE attacks

The issue affects Apache Struts 2 versions 2.0.0 to 2.3.37 (which have been retired), 2.5.0 to 2.5.32, and 6.0.0 to 6.3.0. With a CVSS score of 9.8, the vulnerability poses a critical risk to organizations using the affected versions.

The vulnerability stems from the handling of file uploads in Apache Struts 2. Attackers can upload malicious files to the server, gaining complete control over the system. They also use case-sensitive HTTP parameters to bypass standard security measures.

The implications of this vulnerability are serious, including remote code execution, unauthorized access to sensitive data, system compromise, and potential use as a base for further network attacks.

See also: Vulnerability in Apache Tomcat allows Dos attacks

Apache Struts has already released updates that address the vulnerability. It is recommended that you upgrade immediately to Apache Struts 2.5.33 or Apache Struts 6.3.0.2 and later. Since there are no known workarounds for the vulnerability, upgrading is essential to ensure protection.

Apache Struts

Additionally, organizations using Apache Struts 2 should take additional security measures: restrict file upload settings, implement modern firewalls (WAFs), frequently update their software, and actively monitor for suspicious activity. Prompt action is critical to protecting systems and maintaining security in an environment of growing cyber threats.

Read more: Apache Roller CSRF vulnerability allows privilege escalation

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS