Security News > 2023 > December > New RCE vulnerability in Apache Struts 2 fixed, upgrade ASAP (CVE-2023-50164)
![New RCE vulnerability in Apache Struts 2 fixed, upgrade ASAP (CVE-2023-50164)](/static/build/img/news/new-rce-vulnerability-in-apache-struts-2-fixed-upgrade-asap-cve-2023-50164-medium.jpg)
The Apache Struts project has released updates for the popular open-source web application framework, with fixes for a critical vulnerability that could lead to remote code execution.
The vulnerability affects Apache Struts versions 2.0.0 through 2.5.32 and 6.0.0 through 6.3.0.1, and has been fixed in Apache Struts versions 2.5.33 and 6.3.0.2.
"All developers are strongly advised to perform this upgrade," the Apache Struts project urges.
Vulns in Apache Struts 2 are often leveraged by attackers.
Apache Struts 2 is a modern open-source Java framework for building enterprise-ready web applications.
The 2017 compromise of Equifax's US website and the subsequent massive data breach was the result of an Apache Struts 2 flaw (and lax patching practicesoften exploited by attackers.
News URL
https://www.helpnetsecurity.com/2023/12/08/cve-2023-50164/
Related news
- Critical Git vulnerability allows RCE when cloning repositories with submodules (CVE-2024-32002) (source)
- CISA Warns of Actively Exploited Apache Flink Security Vulnerability (source)
- POC exploit code published for 9.8-rated Apache HugeGraph RCE flaw (source)
- VMware fixes critical vCenter RCE vulnerability, patch now (source)
- Critical RCE Vulnerability Discovered in Ollama AI Infrastructure Tool (source)
- New OpenSSH Vulnerability Could Lead to RCE as Root on Linux Systems (source)