Critical security hole in Apache Struts under exploit
ID: 1b2d089a-ee88-5012-ba60-9c20cd6f25f8
STIX ID: report--1b2d089a-ee88-5012-ba60-9c20cd6f25f8
Feed Name: The Register (Security)
A critical Apache Struts 2 vulnerability (CVE-2024-53677, CVSS 9.5) affecting multiple Struts branches permits attackers to manipulate file upload parameters and perform path traversal through the deprecated File Upload Interceptor, enabling malicious file uploads and potential remote code execution. Public PoC code is available and researchers report active exploitation attempts; maintainers and advisories strongly recommend upgrading to Struts 6.4.0 or later (or the latest supported version) to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
