Lucene search

K
nvd[email protected]NVD:CVE-2023-50164
HistoryDec 07, 2023 - 9:15 a.m.

CVE-2023-50164

2023-12-0709:15:07
CWE-552
web.nvd.nist.gov
6
file upload manipulation
paths traversal
remote code execution
upgrade
struts 2
struts 6

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.09

Percentile

94.6%

An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution.
Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue.

Affected configurations

Nvd
Node
apachestrutsRange2.0.02.5.33
OR
apachestrutsRange6.0.06.3.0.2
VendorProductVersionCPE
apachestruts*cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.09

Percentile

94.6%