CVE-2023-50164 is a critical path traversal vulnerability in Apache Struts that allows attackers to upload malicious files, potentially leading to Remote Code Execution. With a CVSS score of 9.8, it presents a severe risk due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. This vulnerability is being actively exploited in the wild, as evidenced by multiple media reports and a high EPSS score, despite the lack of public exploit code in common repositories like Metasploit or ExploitDB. Users are urged to upgrade to Struts 2.5.33 or 6.3.0.2 or greater immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, <= 2.5.32CPE match | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* | ||
>= 6.0.0, <= 6.3.0.1CPE match | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* | ||
>= 2.0.0, < 2.5.33CPE matchmatch criteria | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.3.0.2CPE matchmatch criteria | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache Struts 2 Vulnerability
Jan 22, 2024Apache Struts 2 Vulnerability
Jan 22, 2024Apache Struts 2 Vulnerability
Jan 22, 2024Apache Struts 2 Vulnerability
Jan 22, 2024Apache Struts 2 Vulnerability
Jan 22, 2024Apache Struts 2 Vulnerability
Jan 22, 2024Apache Struts 2 Vulnerability
Jan 22, 2024Apache Struts 2 Vulnerability
Jan 22, 2024Apache Struts vulnerable to path traversal
Dec 7, 2023Struts: File upload component had a directory traversal vulnerability
Dec 7, 2023