WGSA-2023-00009#
Apache Struts Remote Code Execution Vulnerability (CVE-2023-50164)
Summary #
On December 7th, The Apache Software Foundation disclosed a path traversal vulnerability in the Apache Struts library which could lead to attackers gaining remote code execution with a carefully crafted file upload parameter.
No WatchGuard products are affected by this vulnerability.
CVE identifiers #
| CVE ID | Description | CVSS |
|---|---|---|
| CVE-2023-50164 | An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue. | — |
Product status #
| Product | Affected | Not affected |
|---|
Solution #
No solution has been published for this advisory.