Lucene search

K
cisaCISACISA:848AFE845B4D41B0B59F2090C2571363
HistoryNov 05, 2018 - 12:00 a.m.

Apache Releases Security Advisory for Apache Struts

2018-11-0500:00:00
us-cert.cisa.gov
13

0.059 Low

EPSS

Percentile

93.5%

The Apache Software Foundation has released an advisory to address a vulnerable commons-fileupload library used in Apache Struts versions 2.3.36 and prior. A remote attacker could exploit this vulnerability to take control of an affected system. Struts versions from 2.5.12 are not affected.

NCCIC encourages users and administrators of Apache Struts versions 2.3.36 and prior to review the Apache security advisory for CVE-2016-1000031 and upgrade to the latest released version of Commons FileUpload library, which is currently 1.3.3.

This product is provided subject to this Notification and this Privacy & Use policy.

Please share your thoughts.

We recently updated our anonymous product survey; we’d welcome your feedback.