← volver
CVE-2024-53677criticalexplotación observadaCWE-434

Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks

94Vexday Risk Score

Prioriza la corrección. Ella explotación observada por VulnCheck y tiene prueba de concepto pública.

ssvc Actcvss 9.5epss 78%
de la publicación al arma1 días
Publicada en NVD11 dic
1ª PoC+1d
VulnCheck+4d
probabilidad de explotación
78%top 1% de las CVE
explotación observada
VulnCheck
30 exploit(s) público(s)
File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. This issue affects Apache Struts: from 2.0.0 before 6.4.0. Users are recommended to upgrade to version 6.4.0 at least and migrate to the new file upload mechanism https://struts.apache.org/core-developers/file-upload . If you are not using an old file upload logic based on FileuploadInterceptor your application is safe. You can find more details in  https://cwiki.apache.org/confluence/display/WW/S2-067
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:Y/R:A/V:C/RE:L/U:Red
PoCs públicas encontradas30
githubgithub.com/TAM-K592/CVE-2024-53677-S2-06796githubgithub.com/cloudwafs/s2-067-CVE-2024-536779githubgithub.com/shishirghimir/CVE-2024-53677-Exploit3githubgithub.com/SeanRickerd/CVE-2024-536773githubgithub.com/yangyanglo/CVE-2024-536773githubgithub.com/c4oocO/CVE-2024-53677-Docker3githubgithub.com/dustblessnotdust/CVE-2024-53677-S2-067-thread2githubgithub.com/r007sec/CVE-2024-536772githubgithub.com/punitdarji/Apache-struts-cve-2024-536771githubgithub.com/Cythonic1/CVE-2024-53677-POC1githubgithub.com/ctfsec/CVE-2024-536770githubgithub.com/hiteshpatra/CVE-2024-536770githubgithub.com/hopsypopsy8/CVE-2024-53677-Exploitation0githubgithub.com/BuludX/CVE-2024-536770githubgithub.com/seoyoung-kang/CVE-2024-536770githubgithub.com/sangrok-jeon/CVE-2024-53677-Analysis0vulncheckvulncheck.com/xdb/420179b31365no verificadovulncheckvulncheck.com/xdb/e3d7a1ada72ano verificadovulncheckvulncheck.com/xdb/876d199e276eno verificadovulncheckvulncheck.com/xdb/368a28a635a8no verificadovulncheckvulncheck.com/xdb/61b55ac60446no verificadovulncheckvulncheck.com/xdb/d35919daf052no verificadovulncheckvulncheck.com/xdb/13247b4bfb2fno verificadovulncheckvulncheck.com/xdb/14e5c485502ano verificadovulncheckvulncheck.com/xdb/008477054916no verificadovulncheckvulncheck.com/xdb/20ca58012cc0no verificadovulncheckvulncheck.com/xdb/2af6a2110073no verificadovulncheckvulncheck.com/xdb/915d7d19b4feno verificadovulncheckvulncheck.com/xdb/7aa07cfe88d0no verificadovulncheckvulncheck.com/xdb/567fa5b87fc8no verificado
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.