The Apache Software Foundation over the weekend announced security updates that address a critical-severity file upload vulnerability in the Struts 2 open source development framework, warning that it could be exploited to execute arbitrary code remotely.
According to the organization, the bug impacts Struts versions 2.0.0 to 2.3.37, Struts versions 2.5.0 to 2.5.32, and Struts versions 6.0.0 to 6.3.0.
The vulnerability was patched with the release of Struts versions 2.5.33 and 6.3.0.2.
Apache has credited Steven Seeley of Source Incite for reporting the vulnerability.
The researcher recommends that all Struts 2 users update to a patched release.
In a separate announcement, Apache urges all users to update to the latest web application framework versions, noting that no issues should arise when performing the upgrade.
Apache makes no mention of this vulnerability being exploited in malicious attacks, but Struts flaws have been targeted in the wild, including in attacks against the US credit reporting agency Equifax.
This Cyber News was published on www.securityweek.com. Publication date: Mon, 11 Dec 2023 13:28:05 +0000