Security News

WordPress, Apache Struts Attract the Most Bug Exploits
2020-03-18 21:22

WordPress and Apache Struts vulnerabilities were the most-targeted by cybercriminals in web and application frameworks in 2019 - while input-validation bugs edged out cross-site scripting as the most-weaponized weakness type. The firm found that WordPress and Apache Struts alone accounted for a combined 57 percent of exploited framework bugs during the year.

The Insecurity of WordPress and Apache Struts
2020-03-18 12:45

A study that analyzed all the vulnerability disclosures between 2010 and 2019 found that around 55% of all the security bugs that have been weaponized and exploited in the wild were for two major application frameworks, namely WordPress and Apache Struts. The Drupal content management system ranked third, followed by Ruby on Rails and Laravel, according to a report published this week by risk analysis firm RiskSense.

WordPress and Apache Struts weaponized vulnerabilities on the rise
2020-03-17 05:30

Among the report's key findings, total framework vulnerabilities in 2019 went down but the weaponization rate went up, WordPress and Apache Struts had the most weaponized vulnerabilities, and input validation surpassed cross-site scripting as the most weaponized weakness in the frameworks examined. "Even if best application development practices are used, framework vulnerabilities can expose organizations to security breaches. Meanwhile, upgrading frameworks can be risky because changes can affect the behavior, appearance, or inherent security of applications," said Srinivas Mukkamala, CEO of RiskSense.

61 impacted versions of Apache Struts left off security advisories
2019-08-19 10:23

Researchers found that 24 security advisories inaccurately listed affected versions for the open-source development framework.

Many Apache Struts Security Advisories Updated Following Review
2019-08-16 05:41

Two dozen security advisories for the Apache Struts open source development framework have been updated after researchers determined that they contained incorrect information regarding which...

Stop us if you've heard this one: Remote code hijacking flaw in Apache Struts, patch ASAP
2018-11-07 01:49

Advisory issued over yet another critical security vulnerability The Apache Foundation is urging developers to update their Struts 2 installations and projects using the code – after a critical...

Apache Struts Users Told to Update Vulnerable Component
2018-11-06 14:21

Apache Struts developers are urging users to update a file upload library due to the existence of two vulnerabilities that can be exploited for remote code execution and denial-of-service (DoS)...

Apache Struts Warns Users of Two-Year-Old Vulnerability
2018-11-06 13:27

Users must update their vulnerable libraries manually.

Apache Struts 2.3.x vulnerable to two year old RCE flaw
2018-11-06 11:28

The Apache Software Foundation is urging users that run Apache Struts 2.3.x to update the Commons FileUpload library to close a serious vulnerability that could be exploited for remote code...

What You Need to Know about the Recent Apache Struts Vulnerability
2018-11-05 09:55

Researchers recently revealed a vulnerability in Apache Struts, a popular type of enterprise software. Active exploit attempts weren’t far behind.