{"$schema":"https://docs.oasis-open.org/csaf/csaf/v2.1/schema/csaf.json","document":{"category":"csaf_informational_advisory","csaf_version":"2.1","title":"Apache Struts Remote Code Execution Vulnerability (CVE-2023-50164)","distribution":{"tlp":{"label":"CLEAR"}},"publisher":{"category":"vendor","name":"WatchGuard PSIRT","namespace":"https://www.watchguard.com"},"tracking":{"id":"WGSA-2023-00009","status":"final","version":"22","initial_release_date":"2023-12-15T15:30:18+00:00","current_release_date":"2026-07-28T01:18:27.285483+00:00","revision_history":[{"date":"2023-12-15T15:30:18+00:00","number":"22","summary":"Initial release."}]},"references":[{"summary":"vendor-advisory","url":"https://psirt.watchguard.com/WGSA-2023-00009"},{"summary":"cve","url":"https://www.cve.org/CVERecord?id=CVE-2023-50164"}],"notes":[{"category":"summary","text":"On December 7th, The Apache Software Foundation disclosed a path traversal vulnerability in the Apache Struts library which could lead to attackers gaining remote code execution with a carefully crafted file upload parameter.\n\nNo WatchGuard products are affected by this vulnerability.","title":"Summary"}]}}