CVE-2023-50164
An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 80.8%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 80.82% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-552
- Affected
- apache/struts
- Source
- security@apache.org
References
- http://packetstormsecurity.com/files/176157/Struts-S2-066-File-Upload-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- https://lists.apache.org/thread/yh09b3fkf6vz5d6jdgrlvmg60lfwtqhjMailing List, Patch
- https://security.netapp.com/advisory/ntap-20231214-0010/Third Party Advisory, VDB Entry
- https://www.openwall.com/lists/oss-security/2023/12/07/1Mailing List
- http://packetstormsecurity.com/files/176157/Struts-S2-066-File-Upload-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- https://lists.apache.org/thread/yh09b3fkf6vz5d6jdgrlvmg60lfwtqhjMailing List, Patch
- https://security.netapp.com/advisory/ntap-20231214-0010/Third Party Advisory, VDB Entry
- https://www.openwall.com/lists/oss-security/2023/12/07/1Mailing List
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.