logo

Critical Apache Struts File Upload Vulnerability (CVE-2024-53677)—Risks, Implications, and Enterprise Countermeasures

ID: dd389c59-8b30-5fc7-bc53-8afa0b8372c6

STIX ID: report--dd389c59-8b30-5fc7-bc53-8afa0b8372c6

Feed Name: Qualys Blog

Threat Score
75/100

Date Published: 2024-12-17

Date Updated: 2026-04-28

Author: Saeed Abbasi

...
...

Apache disclosed a critical vulnerability (CVE-2024-53677) in Apache Struts' file upload mechanism that allows path traversal and, under certain conditions, remote code execution against Struts 2.0.0–2.3.37 (EOL), 2.5.0–2.5.33, and 6.0.0–6.3.0.2; organizations are advised to upgrade to Struts 6.4.0+ and migrate to the new file upload mechanism. The report includes Qualys detection QIDs, recommended QQL queries, Software Composition Analysis guidance, and mitigation options via Qualys VMDR, Patch Management, and TruRisk, but does not report active exploitation in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.