WGSA-2023-00009

Apache Struts Remote Code Execution Vulnerability (CVE-2023-50164)

Informational Published 2023-12-15Updated 2026-07-28

Summary #

On December 7th, The Apache Software Foundation disclosed a path traversal vulnerability in the Apache Struts library which could lead to attackers gaining remote code execution with a carefully crafted file upload parameter.

No WatchGuard products are affected by this vulnerability.

CVE identifiers #

CVE IDDescriptionCVSS
CVE-2023-50164 An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue.

Product status #

ProductAffectedNot affected

Solution #

No solution has been published for this advisory.

References #