Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Apache Struts Critical Vulnerability Discovered, Exploitation Attempts Discovered
Global Security

Apache Struts Critical Vulnerability Discovered, Exploitation Attempts Discovered

AdminBy AdminDecember 18, 2024No Comments2 Mins Read
Critical Apache Struts Flaw
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


December 18, 2024Ravi LakshmananCyber ​​Attack / Vulnerability

A critical flaw in Apache Struts

Threat actors are attempting to exploit a recently disclosed security flaw affecting Apache Struts that could open the way for remote code execution.

Issue tracked as CVE-2024-53677has a CVSS score of 9.5 out of 10.0, indicating critical severity. This vulnerability is similar to another critical bug that the developers of the project fixed in December 2023. (CVE-2023-50164CVSS score: 9.8) that too came under active exploitation shortly after public disclosure.

Cyber ​​security

“An attacker could manipulate file download parameters to allow path traversal, and under some circumstances this could lead to the download of a malicious file that could be used to execute remote code,” it said. Apache Consulting.

In other words, successful exploitation of the flaw could allow an attacker to download arbitrary payloads to vulnerable instances, which could then be used to execute commands, steal data, or download additional payloads for later use.

The vulnerability affects the following versions and was fixed in Struts 6.4.0 or higher –

  • Struts 2.0.0 – Struts 2.3.37 (End of Life),
  • Struts 2.5.0 – Struts 2.5.33 and
  • Struts 6.0.0 – Struts 6.3.0.2

Dr. Johannes Ulrich, dean of research at the SANS Institute of Technology, said that an incomplete patch for CVE-2023-50164 could have led to a new problem by adding exploits that match publicly published proof-of-concept (PoC) were discovered in the wild.

“At the moment, exploit attempts are trying to list vulnerable systems,” Ulrich noted. Next, the attacker tries to find the downloaded script. So far, scans come only from 169.150.226(.)162″.

Cyber ​​security

To reduce the risk, users are advised to upgrade to the latest version as soon as possible and rewrite their code to use the new version Action file download mechanism and an associated interceptor.

“Apache Struts is at the heart of many enterprise IT stacks, powering public portals, internal productivity applications, and critical business workflows,” said Saeed Abbasi, Product Manager, Threat Research, Qualys. said. “Its popularity in high-stakes contexts means that a vulnerability like CVE-2024-53677 can have far-reaching consequences.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025

67 Trojanized GitHub repository found in the company, orientation on gamers and developers

June 20, 2025

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025

67 Trojanized GitHub repository found in the company, orientation on gamers and developers

June 20, 2025

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.