PT-2024-9392 · Apache · Apache Struts

·

CVE-2024-53677

·

Published

2024-11-26

·

Updated

2025-09-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Summary

Name of the Vulnerable Software and Affected Versions: Apache Struts versions 2.0.0 through 2.3.37, 2.5.0 through 2.5.33, and 6.0.0 through 6.3.0.2.
Description
A critical flaw exists in the file upload logic of Apache Struts. An attacker can manipulate file upload parameters to enable path traversal, potentially leading to the upload of a malicious file and subsequent Remote Code Execution (RCE). Exploitation is actively occurring in the wild, with proof-of-concept exploits available. Successful exploitation could allow an attacker to install programs, view, change, or delete data, or create new accounts with full user rights, depending on the privileges of the affected service account.
Recommendations
Upgrade to version 6.4.0 or later and migrate to the new file upload mechanism. If utilizing a configuration that does not use the FileUploadInterceptor, the application is not vulnerable.

Exploit

Fix

RCE

LPE

Path traversal

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-11084
CVE-2024-53677
GHSA-43MQ-6XMG-29VM

Affected Products

Apache Struts