Critical Apache Struts Vulnerability CVE-2024-53677 Exploited for Remote Code Execution: Urgent Patch Required
Threat actors are exploiting a critical security flaw in Apache Struts, identified as CVE-2024-53677, which has a CVSS score of 9.5, indicating high severity. This vulnerability allows remote code execution through file upload parameter manipulation, leading to path traversal and potential malicious file uploads. It impacts Struts versions 2.0.0 to 2.3.37, 2.5.0 to 2.5.33, and 6.0.0 to 6.3.0.2, but has been patched in version 6.4.0 or higher. The flaw is similar to a previously exploited vulnerability (CVE-2023-50164). Users are advised to upgrade immediately and adopt the new Action File Upload mechanism to mitigate risks. Exploit attempts have been observed in the wild, originating from a specific IP address. The vulnerability's impact is significant due to Apache Struts' widespread use in critical business applications.
https://thehackernews.com/2024/12/patch-alert-critical-apache-struts-flaw.html
Comments
Post a Comment