Security News > 2020 > August > PoC Exploit Targeting Apache Struts Surfaces on GitHub

PoC Exploit Targeting Apache Struts Surfaces on GitHub
2020-08-14 21:20

Proof-of-concept exploit code surfaced on GitHub on Friday, raising the stakes on two existing Apache Struts 2 bugs that allow for remote code-execution and denial-of-service attacks on vulnerable installations.

Remediation includes upgrading to Struts 2.5.22, according to the Apache Struts Security Team.

Researchers have warned of outdated installations of Apache Struts 2 and that if left unpatched they can open the door to more critical holes similar to a bug at the root of the massive Equifax breach, which was also an Apache Struts 2 flaw.

While the PoC attack and exploit posted to GitHub targets CVE-2019-0230, the Apache Struts Security Team also urged users to patch for the DoS bug.

The Apache security bulletin recommends upgrading to the most recent version of Apache Struts.


News URL

https://threatpost.com/poc-exploit-github-apache-struts/158393/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Apache 281 13 544 711 366 1634
Github 13 2 45 30 19 96