PT-2024-9392 · Apache · Apache Struts
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Vulnerability Summary
Name of the Vulnerable Software and Affected Versions: Apache Struts versions 2.0.0 through 2.3.37, 2.5.0 through 2.5.33, and 6.0.0 through 6.3.0.2.
Description
A critical flaw exists in the file upload logic of Apache Struts. An attacker can manipulate file upload parameters to enable path traversal, potentially leading to the upload of a malicious file and subsequent Remote Code Execution (RCE). Exploitation is actively occurring in the wild, with proof-of-concept exploits available. Successful exploitation could allow an attacker to install programs, view, change, or delete data, or create new accounts with full user rights, depending on the privileges of the affected service account.
Recommendations
Upgrade to version 6.4.0 or later and migrate to the new file upload mechanism. If utilizing a configuration that does not use the
FileUploadInterceptor, the application is not vulnerable.Exploit
Fix
RCE
LPE
Path traversal
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Struts