HomeSecurityCritical vulnerability identified in Apache Struts - Update immediately!

Critical vulnerability identified in Apache Struts – Update immediately!

Malicious actors are exploiting a recently discovered vulnerability in Apache Struts (CVE-2024-53677, CVSS 9.5), which could allow remote code execution (RCE).

apache struts

Read more: Apache Struts: Hackers exploit critical vulnerability

The vulnerability is related to weaknesses in file handling during the upload process, allowing malicious files to be uploaded. These files can be used to execute commands, extract data, or download additional payloads.

Affected versions include Struts 2.0.0 – 2.3.37, 2.5.0 – 2.5.33, and 6.0.0 – 6.3.0.2. The issue has been fixed in Struts 6.4.0 and later.

See also: Apache Roller CSRF vulnerability allows privilege escalation

According to Dr. Johannes Ullrich (SANS Technology Institute), the vulnerability may stem from an incomplete patch of an older vulnerability (CVE-2023-50164, CVSS 9.8). Exploitation attempts based on Proof-of-Concept (PoC) have already been observed, with a scan from IP address 169.150.226[.]162.

Critical vulnerability identified in Apache Struts - Update immediately!

System administrators are advised to immediately upgrade to the latest version and adapt their applications to the new Action File Upload.

Read more: Vulnerability in Atlassian Sourcetree allows code execution

Given the widespread use of Apache Struts in critical business applications, this vulnerability could have serious implications, as warned by Saeed Abbasi from Qualys.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS