Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
0

CVE-2024-53677

Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

File upload logic is flawed vulnerability in Apache Struts.

This issue affects Apache Struts: from 2.0.0 before 6.4.0.

Users are recommended to upgrade to version 6.4.0, which fixes the issue.

You can find more details in  https://cwiki.apache.org/confluence/display/WW/S2-067

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

General Information

Vendors

  • Apache Software Foundation

Products

  • Apache Struts

References

Exploit
PoCs that have not been added by contributors directly have been sourced from: nomi-sec/PoC-in-GitHub.
A PoC added here by the AKB Worker must have at least 2 GitHub stars.

Additional Info

Technical Analysis