vulnerability

Apache Struts: S2-066 (CVE-2023-50164): Security updates available for Apache Struts

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Dec 8, 2023
Added
Dec 8, 2023
Modified
Feb 20, 2025

Description

An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution.
Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue.

Solution(s)

apache-struts-upgrade-2_5_33apache-struts-upgrade-6_3_0_2
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.