← Back

CVE-2023-50164

nvd nist
Published: Dec 7, 2023Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue.

Affected (2)

Products: Apache: Struts
1 product
Struts
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 2.0.0 to 2.5.33
From 6.0.0 to 6.3.0.2

References (8)

Source: security@apache.org
Mailing ListPatch
Source: security@apache.org
Third Party AdvisoryVDB Entry
Source: security@apache.org
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List

Timeline

No history available yet.