VDB
Sign up
CRITICAL10.0

GHSA-j77q-2qqg-6989

Apache Struts vulnerable to remote arbitrary command execution due to improper input validation

Quick fix

GHSA-j77q-2qqg-6989 — org.apache.struts:struts2-core: upgrade to the fixed version with the command below.

# pom.xml: bump <version>2.3.32</version> for org.apache.struts:struts2-core

Details

Apache Struts versions prior to 2.3.32 and 2.5.10.1 contain incorrect exception handling and error-message generation during file-upload attempts using the Jakarta Multipart parser, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.struts:struts2-core
Introduced in: 2.3.0Fixed in: 2.3.32
Fix# pom.xml: bump <version>2.3.32</version> for org.apache.struts:struts2-core
Maven/org.apache.struts:struts2-core
Introduced in: 2.5.0Fixed in: 2.5.10.1
Fix# pom.xml: bump <version>2.5.10.1</version> for org.apache.struts:struts2-core

References