Critical Apache Struts Vulnerability CVE-2024-53677 Exploited for Remote Code Execution: Urgent Patch Required

Threat actors are exploiting a critical security flaw in Apache Struts, identified as CVE-2024-53677, which has a CVSS score of 9.5, indicating high severity. This vulnerability allows remote code execution through file upload parameter manipulation, leading to path traversal and potential malicious file uploads. It impacts Struts versions 2.0.0 to 2.3.37, 2.5.0 to 2.5.33, and 6.0.0 to 6.3.0.2, but has been patched in version 6.4.0 or higher. The flaw is similar to a previously exploited vulnerability (CVE-2023-50164). Users are advised to upgrade immediately and adopt the new Action File Upload mechanism to mitigate risks. Exploit attempts have been observed in the wild, originating from a specific IP address. The vulnerability's impact is significant due to Apache Struts' widespread use in critical business applications.

https://thehackernews.com/2024/12/patch-alert-critical-apache-struts-flaw.html

Comments

Popular posts from this blog

Endor Labs Announces Integrated SAST Offerings

OWASP Releases Enhanced Dependency-Check Tool with Advanced Tagging and Policy Management Features

The Hidden Cost of DevSecOps: Time and Financial Burden of Security on Developers