logo

Apache issues patches for critical Struts 2 RCE bug

ID: 300d5a67-6479-5726-9c2d-4cf5ce7ce17e

STIX ID: report--300d5a67-6479-5726-9c2d-4cf5ce7ce17e

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2024-12-12

Date Updated: 2026-04-26

Author: Connor Jones

...
...

CVE-2024-53677 is a high-severity remote code execution vulnerability in Apache Struts that allows attackers to manipulate file upload parameters to achieve path traversal and potentially upload malicious files leading to RCE. Apache advises upgrading to Struts 6.4.0+ (which removes the deprecated File Upload Interceptor) because there is no workaround; affected versions include Struts 2.0.0–2.3.37, 2.5.0–2.5.33, and 6.0.0–6.3.0.2. The report highlights strong CVSS scores (9.5–9.8), the widespread usage of Struts, and historical impact of Struts vulnerabilities (e.g., the Equifax incident), underscoring significant risk until systems are patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.