Apache Struts Remote Code Execution Vulnerability
Release Date: 16 Dec 2024
RISK: Medium Risk
TYPE: Servers - Web Servers
A vulnerability has been identified in Apache Struts. A remote attacker can exploit this vulnerability to trigger remote code execution on the targeted system.
Impact
- Remote Code Execution
System / Technologies affected
- Struts 2.0.0 - Struts 2.3.37 (EOL)
- Struts 2.5.0 - Struts 2.5.33
- Struts 6.0.0 - Struts 6.3.0.2
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to Struts 6.4.0 or greater and use Action File Upload Interceptor
沒有留言:
發佈留言