On December 7, 2023, the following vulnerability in Apache Struts was disclosed:
CVE-2023-50164: An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution.
For a description of this vulnerability, see the Apache Software Foundation Security Bulletin [βhttps://cwiki.apache.org/confluence/display/WW/S2-066β].
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-struts-C2kCMkmT [βhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-struts-C2kCMkmTβ]
Vendor | Product | Version | CPE |
---|---|---|---|
cisco | identity_services_engine_software | any | cpe:2.3:a:cisco:identity_services_engine_software:any:*:*:*:*:*:*:* |