HomeSecurityPoC Exploit released for RCE Apache Struts vulnerability

PoC Exploit released for Apache Struts RCE vulnerability

A proof-of-concept (PoC) exploit for the critical Apache Struts RCE vulnerability, CVE-2024-53677, has been publicly released, causing alarm throughout the cybersecurity.

See also: Critical vulnerability identified in Apache Struts – Update immediately!

Apache Struts RCE

This vulnerability, which is rated 9.5 on the CVSS scale, allows attackers to execute arbitrary code remotely by exploiting flaws in the framework's file upload mechanism.

The RCE vulnerability affects Apache Struts versions 2.0.0 to 2.5.33 and 6.0.0 to 6.3.0.2, with a fix available in version 6.4.0 and later.

The vulnerability stems from a path traversal flaw in the deprecated " FileUploadInterceptor " component of Apache Struts, a widely used Java- based web application framework .

By manipulating file upload parameters, attackers can bypass security restrictions to upload malicious files to unauthorized directories. This can lead to:

See also: RCE vulnerability in Apache Struts 2 puts servers at risk

  • Path Traversal: Uploading files to arbitrary locations within the server.
  • Remote Code Execution (RCE): Execution of malicious code, such as web shells or binary payloads, to gain complete control of the compromised system.
  • Category Flaw CWE-434: Unrestricted file upload of dangerous type, a type of vulnerability that has historically led to significant breaches.
PoC Exploit released for Apache Struts RCE vulnerability

The release of the PoC exploit code has significantly escalated the risk of mass exploitation.

Security researchers have observed early indicators of active attacks targeting vulnerable systems, with automated tools being leveraged to detect and exploit vulnerable Apache Struts instances.

Given the widespread adoption of Apache Struts in enterprise environments, this RCE vulnerability poses a serious threat to organizations relying on older versions of the framework.

The Apache Software Foundation has strongly advised all users to upgrade to version 6.4.0 or later immediately.

See also: Apache HertzBeat vulnerability allows exploitation of sensitive data

A Remote Code Execution (RCE) vulnerability is a critical security flaw that allows an attacker to execute arbitrary code on a target system remotely. This type of vulnerability can occur when software mishandles input data or fails to sanitize user-supplied data, allowing malicious actors to input and execute their own commands. RCE attacks can have devastating consequences, including unauthorized access, data theft, system compromise, and even control of an organization's network. Mitigating RCE flaws requires safe coding practices, regular testing, timely patching , and the implementation of robust intrusion detection systems.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS