logo

A Vulnerability in Apache Struts2 Could Allow for Remote Code Execution

ID: 3c148fe4-1d4c-5046-b9fc-ba2d769fe8c3

STIX ID: report--3c148fe4-1d4c-5046-b9fc-ba2d769fe8c3

Feed Name: CISecurity.org Advisories

Threat Score
70/100

Date Published: 2024-12-23

Date Updated: 2026-04-27

...
...

A file upload vulnerability in Apache Struts2 (CVE-2024-53677) allows attackers to exploit path traversal during uploads to achieve remote code execution; successful exploitation can run code as the affected service account and potentially lead to installation of programs, data access/modification, or creation of privileged accounts depending on the service account's privileges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.