Categories: Security News

Widespread Exploitation of Critical Apache Struts 2 Vulnerability

Global attackers actively exploit a severe vulnerability in Apache Struts 2, a popular open-source framework for developing Java web applications and websites. This alert comes from Australian and French authorities who anticipate widespread abuse. The Apache Foundation responded on December 7 with security updates to address this vulnerability, CVE-2023-50164.

In 2017, a similar critical flaw in Struts was exploited to steal data from over 147 million Americans from the U.S. credit bureau Equifax. The current vulnerability being exploited allows attackers to change file upload parameters. This leads to path traversal and the uploading of harmful files, ultimately enabling remote code execution, where the attacker gains control over the affected system.

Recently, the Shadowserver Foundation observed attacks using previously developed proof-of-concept exploit code. The Australian Cyber Security Centre (ACSC), the French Computer Emergency Response Team (CERT-FR), and the internet giant Akamai have also reported misuse. Authorities advise organizations to update their Struts-based applications as they expect extensive abuse. Through this security loophole, attackers can install a backdoor or web shell, allowing sustained access to the compromised server and enabling further malicious activities.

Max Reisler

Greetings! I'm Max, part of our malware removal team. Our mission is to stay vigilant against evolving malware threats. Through our blog, we keep you updated on the latest malware and computer virus dangers, equipping you with the tools to safeguard your devices. Your support in spreading this valuable information across social media is invaluable in our collective effort to protect others.

Recent Posts

Remove Gaming-news-tab.com browser hijacker virus

Upon closer inspection, Gaming-news-tab.com is more than just a browser tool. It's actually a browser…

22 hours ago

Remove Finditfasts.com browser hijacker virus

Upon closer inspection, Finditfasts.com is more than just a browser tool. It's actually a browser…

22 hours ago

Remove Hotsearch.io browser hijacker virus

Upon closer inspection, Hotsearch.io is more than just a browser tool. It's actually a browser…

2 days ago

Remove Laxsearch.com browser hijacker virus

Upon closer inspection, Laxsearch.com is more than just a browser tool. It's actually a browser…

2 days ago

Remove VEPI ransomware (Decrypt VEPI files)

Every passing day makes ransomware attacks more normal. They create havoc and demand a monetary…

3 days ago

Remove VEHU ransomware (Decrypt VEHU files)

Every passing day makes ransomware attacks more normal. They create havoc and demand a monetary…

3 days ago