Lucene search

K
f5F5F5:K000137931
HistoryDec 15, 2023 - 12:00 a.m.

K000137931 : Apache Struts vulnerability CVE-2023-50164

2023-12-1500:00:00
my.f5.com
21
apache struts
vulnerability
file upload
path traversal
remote code execution
upgrade
versions
f5 products

7.1 High

AI Score

Confidence

Low

0.09 Low

EPSS

Percentile

94.7%

Security Advisory Description

An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue. (CVE-2023-50164)

Impact

There is no impact; F5 products are not affected by this vulnerability.