Critical Apache Struts File Upload Vulnerability (CVE-2024-53677)—Risks, Implications, and Enterprise Countermeasures
ID: dd389c59-8b30-5fc7-bc53-8afa0b8372c6
STIX ID: report--dd389c59-8b30-5fc7-bc53-8afa0b8372c6
Feed Name: Qualys Blog
Apache disclosed a critical vulnerability (CVE-2024-53677) in Apache Struts' file upload mechanism that allows path traversal and, under certain conditions, remote code execution against Struts 2.0.0–2.3.37 (EOL), 2.5.0–2.5.33, and 6.0.0–6.3.0.2; organizations are advised to upgrade to Struts 6.4.0+ and migrate to the new file upload mechanism. The report includes Qualys detection QIDs, recommended QQL queries, Software Composition Analysis guidance, and mitigation options via Qualys VMDR, Patch Management, and TruRisk, but does not report active exploitation in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
