{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aapachestruts/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2024-53677"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Struts (2.0.0-6.3.0.2)"],"_cs_severities":["critical"],"_cs_tags":["apache-struts","rce","file-upload","web-application-attack"],"_cs_type":"advisory","_cs_vendors":["Apache"],"content_html":"\u003cp\u003eApache Struts versions 2.0.0 through 6.3.0.2 are vulnerable to a remote code execution (RCE) flaw, tracked as CVE-2024-53677 (also identified as S2-067). The vulnerability resides in the framework's file upload logic, specifically within the FileUploadInterceptor component. An unauthenticated attacker can manipulate file upload parameters to perform path traversal, enabling them to upload arbitrary files to locations outside of the intended directory. By placing executable files, such as .jsp scripts, into web-accessible directories, an attacker can achieve remote code execution. Because this vulnerability involves a significant change to the file upload mechanism, the vendor notes that the fix in version 6.4.0 is not backward compatible, requiring organizations to refactor existing Action classes. The CVSS 9.8 rating reflects the ease of exploitation, as it requires no privileges or user interaction.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an internet-facing application utilizing a vulnerable version of the Apache Struts framework.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP POST request targeting the /upload.action endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker injects path traversal sequences (e.g., ../) into the filename parameter of the multipart/form-data request body.\u003c/li\u003e\n\u003cli\u003eThe FileUploadInterceptor fails to sanitize the input, allowing the attacker to traverse the filesystem directory structure.\u003c/li\u003e\n\u003cli\u003eThe server writes the attacker-supplied malicious file (e.g., a webshell) to an arbitrary, attacker-controlled location within the web root.\u003c/li\u003e\n\u003cli\u003eAttacker sends a secondary HTTP GET request to the path of the newly uploaded file to trigger script execution.\u003c/li\u003e\n\u003cli\u003eThe application server executes the malicious script, granting the attacker arbitrary code execution on the underlying host.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full system compromise, including unauthorized access to sensitive data, potential lateral movement within the network, and complete control over the affected application server. This vulnerability affects all organizations utilizing Apache Struts within the specified version range (2.0.0-6.3.0.2).\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all Apache Struts deployments to version 6.4.0 or later immediately to patch CVE-2024-53677.\u003c/li\u003e\n\u003cli\u003eAudit web server logs for suspicious POST requests targeting \u0026quot;/upload.action\u0026quot; that contain path traversal sequences (e.g., \u0026quot;..\u0026quot;, \u0026quot;%2e%2e\u0026quot;) in the filename or form parameters.\u003c/li\u003e\n\u003cli\u003ePerform code refactoring as necessary to support the new file upload mechanism introduced in version 6.4.0, as it is not backward compatible with previous implementations.\u003c/li\u003e\n\u003cli\u003eImplement Web Application Firewall (WAF) rules to inspect multipart form data for traversal characters in the filename field.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-15T10:28:25Z","date_published":"2026-09-15T10:28:25Z","id":"https://feed.craftedsignal.io/briefs/2026-09-apache-struts-rce/","summary":"A critical remote code execution vulnerability (CVE-2024-53677) in Apache Struts versions 2.0.0 through 6.3.0.2 allows attackers to leverage path traversal during file uploads to execute arbitrary code.","title":"Critical RCE Vulnerability in Apache Struts (S2-067)","url":"https://feed.craftedsignal.io/briefs/2026-09-apache-struts-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}