Yet Another Apache Struts 2 Vulnerability – CVE-2023-50164
ID: 751c9e1c-a419-5309-88ac-41ef9ee8e11c
STIX ID: report--751c9e1c-a419-5309-88ac-41ef9ee8e11c
Feed Name: Qualys Blog
Threat Score
CVE-2023-50164 is a critical (CVSS 9.8) remote code execution vulnerability in Apache Struts 2 that permits malicious file uploads in specified 2.0.x–2.3.37, 2.5.0–2.5.32, and 6.0.0–6.3.0 releases. The report describes Qualys WAS detection (QID 150774) which attempts non-malicious file uploads to identify vulnerable servers, recommends upgrading to Struts 2.5.33 / 6.3.0.2 or later, using WAF protections, and retesting to confirm remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
