logo

Yet Another Apache Struts 2 Vulnerability – CVE-2023-50164

ID: 751c9e1c-a419-5309-88ac-41ef9ee8e11c

STIX ID: report--751c9e1c-a419-5309-88ac-41ef9ee8e11c

Feed Name: Qualys Blog

Threat Score
75/100

Date Published: 2023-12-26

Date Updated: 2026-04-28

Author: Sheela Sarva

...
...

CVE-2023-50164 is a critical (CVSS 9.8) remote code execution vulnerability in Apache Struts 2 that permits malicious file uploads in specified 2.0.x–2.3.37, 2.5.0–2.5.32, and 6.0.0–6.3.0 releases. The report describes Qualys WAS detection (QID 150774) which attempts non-malicious file uploads to identify vulnerable servers, recommends upgrading to Struts 2.5.33 / 6.3.0.2 or later, using WAF protections, and retesting to confirm remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.