Orgs Scramble to Fix Actively Exploited Bug in Apache Struts 2
ID: 05fccebd-9edd-5b35-b129-847ca61bd7c1
STIX ID: report--05fccebd-9edd-5b35-b129-847ca61bd7c1
Feed Name: Dark Reading
Threat Score
Apache Struts 2 is affected by a critical RCE vulnerability (CVE-2024-53677, CVSS 9.5) in the File Upload Interceptor that enables path traversal and remote code execution; public PoCs and observed exploitation attempts have been reported, remediation requires migrating to a new Action File Upload Interceptor with code changes rather than a simple patch, and tens of thousands of vulnerable instances were observed, prompting warnings from multiple national cybersecurity centers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
