Vulnerabilities/

Apache Struts 2 RCE S2-045

Severity:
High

Description

Apache Struts 2 suffers from a Remote Code Execution (RCE) vulnerability, designated as S2-045. This vulnerability allows attackers to execute arbitrary commands on the server by exploiting a flaw in the way Apache Struts handles certain Content-Type values. When an invalid Content-Type value is provided, an exception is thrown, revealing an error message that can be leveraged by attackers.

Recommendation

To mitigate this vulnerability, if you are using the Jakarta-based file upload Multipart parser, it is recommended to upgrade to Apache Struts version 2.3.32 or 2.5.10.1, or newer versions.

References

Related Issues

Tags:
RCE
Struts
Injection
Anything's wrong? Let us know Last updated on May 13, 2024

This issue is available in SmartScanner Professional

See Pricing