logo

Detect and Manage the Risk of Apache Struts (CVE-2023-50164) Comprehensively

ID: a01b211e-1159-5a56-9cd0-bd599bd7c73b

STIX ID: report--a01b211e-1159-5a56-9cd0-bd599bd7c73b

Feed Name: Qualys Blog

Threat Score
75/100

Date Published: 2024-01-12

Date Updated: 2026-04-28

Author: Spencer Brown

...
...

This Qualys advisory details CVE-2023-50164, a critical Apache Struts 2 file-upload/path-traversal vulnerability allowing unauthenticated remote code execution; it notes observed exploitation starting December 13, 2023, lists affected and fixed versions, and provides detection and mitigation guidance—promoting Qualys VMDR, SwCA (Software Composition Analysis), WAS, Container Security QIDs, and remediation/prioritization workflows to locate deep-embedded Struts packages and reduce risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.