CVE-2023-50164
CRITICAL 9.8EPSS 80.8%
An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution.Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 80.82% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2023-12-07
- Updated
- 2025-03-14
Proof-of-concept exploits (17)
- AsfandAliMemon25/CVE-2023-50164Analysis-0★ · 2024-04-16
- MKIRAHMET/CVE-2023-50164-HTB-strutted0★ · 2025-09-04
- NikitaPark/CVE-2023-50164-PoC1★ · 2026-08-10
- Pixel-DefaultBR/CVE-2023-501641★ · 2025-03-07
- Thirukrishnan/CVE-2023-50164-Apache-Struts-RCE1★ · 2023-12-20
- Trackflaw/CVE-2023-50164-ApacheStruts2-Docker7★ · 2023-12-20
- aaronm-sysdig/cve-2023-501641★ · 2024-01-01
- alvaromcarmena/StrutsShell-PoC0★ · 2024-09-16
- bcdannyboy/CVE-2023-501644★ · 2023-12-15
- c4oocO/CVE-2024-53677-Docker3★ · 2024-12-17
- dwisiswant0/cve-2023-50164-poc57★ · 2023-12-18
- helsecert/cve-2023-501641★ · 2023-12-18
- henrikplate/struts-demo6★ · 2023-12-20
- ilikeoyt/go-Attack2★ · 2025-02-19
- jakabakos/CVE-2023-50164-Apache-Struts-RCE86★ · 2025-11-03
- snyk-labs/CVE-2023-50164-POC6★ · 2025-12-04
- sunnyvale-it/CVE-2023-50164-PoC2★ · 2024-01-16