Back

CRITICAL

Apache Struts: File upload component had a directory traversal vulnerability

Published Dec 7, 2023

Description

An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Dec 7, 2023
Updated Mar 14, 2025
Reserved Dec 4, 2023
CISA Vulnrichment
Updated Dec 16, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Dec 7, 2023
GHSA-2J39-QCJM-428W