Four in five Apache Struts 2 downloads are for versions featuring critical flaw
ID: d06de87f-4d73-5e0e-ae26-17bae466f855
STIX ID: report--d06de87f-4d73-5e0e-ae26-17bae466f855
Feed Name: The Register (Security)
Sonatype and other researchers reported a critical remote-code-execution flaw (CVE-2023-50164, CVSS 9.8) in Apache Struts 2's file upload handling that can allow attackers to upload webshells and gain control of servers. Despite available fixes, Sonatype observed roughly 80% of Struts downloads were for vulnerable versions and active exploitation attempts were seen; researchers warn exploitation requires specific preconditions but advise urgent patching and inventorying of Struts components.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
