跳转到帖子

Apache Struts: S2-067 (CVE-2024-53677): Security updates available for Apache Struts

recommended_posts

发布于
  • Members

Apache Struts: S2-067 (CVE-2024-53677): Security updates available for Apache Struts

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
12/12/2024
Created
12/13/2024
Added
12/12/2024
Modified
12/23/2024

Description

File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. This issue affects Apache Struts: from 2.0.0 before 6.4.0. Users are recommended to upgrade to version 6.4.0 at least and migrate to the newfile upload mechanism https://struts.apache.org/core-developers/file-upload . If you are not using an old file upload logic based on FileuploadInterceptor your application is safe. You can find more details in  https://cwiki.apache.org/confluence/display/WW/S2-067

Solution(s)

  • apache-struts-upgrade-6_4_0

References

  • https://attackerkb.com/topics/cve-2024-53677
  • CVE - 2024-53677
  • https://cwiki.apache.org/confluence/display/WW/S2-067
  • 查看数 700
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…