https://seclists.org/oss-sec/2023/q4/263: CVE-2023-50164: Apache Struts: File upload component had a directory traversal vulnerability
Published Dec 7, 2023
·Updated
Affected Software
1 affected component
Apache struts>=2.0.0<2.5.32, >=6.0.0<6.3.0.1
Frequently Asked Questions
1
What is the severity of CVE-2023-50164?
The severity of CVE-2023-50164 is classified as critical.
2
What versions of Apache Struts are affected by CVE-2023-50164?
CVE-2023-50164 affects Apache Struts versions 2.0.0 through 2.5.32 and 6.0.0 through 6.3.0.1.
3
How does CVE-2023-50164 vulnerability affect Apache Struts?
CVE-2023-50164 allows an attacker to manipulate file upload parameters, potentially leading to directory traversal and malicious file uploads.
4
How do I fix CVE-2023-50164?
To fix CVE-2023-50164, upgrade to the patched versions of Apache Struts that are beyond the affected versions.
5
Can CVE-2023-50164 be exploited remotely?
Yes, CVE-2023-50164 can be exploited remotely, allowing attackers to upload malicious files if the conditions are met.