CVE-2024-53677
CRITICAL 9.8EPSS 78.2%
File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution.This issue affects Apache Struts: from 2.0.0 before 6.4.0.Users are recommended to upgrade to version 6.4.0 at least and migrate to the new file upload mechanism https://struts.apache.org/core-developers/file-upload . If you are not using an old file upload logic based on FileuploadInterceptor your application is safe.You can find more details in https://cwiki.apache.org/confluence/display/WW/S2-067
- CVSS v4.0
- 9.5 CRITICAL
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:C/RE:L/U:Red - CVSS v4.0
- 9.5 CRITICAL
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:Y/R:A/V:C/RE:L/U:Red - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 78.20% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2024-12-11
- Updated
- 2025-01-03
Proof-of-concept exploits (20)
- 0xPThree/struts_cve-2024-536770★ · 2025-01-07
- 0xdeviner/CVE-2024-536770★ · 2024-12-23
- BuludX/CVE-2024-536770★ · 2025-07-20
- Cythonic1/CVE-2024-53677-POC1★ · 2025-09-24
- EQSTLab/CVE-2024-5367717★ · 2025-01-03
- SeanRickerd/CVE-2024-536773★ · 2025-03-05
- TAM-K592/CVE-2024-53677-S2-06796★ · 2024-12-20
- c4oocO/CVE-2024-53677-Docker3★ · 2024-12-17
- cloudwafs/s2-067-CVE-2024-536779★ · 2024-12-17
- dustblessnotdust/CVE-2024-53677-S2-067-thread2★ · 2024-12-18
- hopsypopsy8/CVE-2024-53677-Exploitation0★ · 2025-02-13
- punitdarji/Apache-struts-cve-2024-536771★ · 2025-01-11
- r007sec/CVE-2024-536772★ · 2025-06-03
- saad0x1/Exploits1★ · 2025-09-07
- shishirghimir/CVE-2024-53677-Exploit3★ · 2025-02-24
- yangyanglo/CVE-2024-536773★ · 2024-12-17
- hiteshpatra/CVE-2024-53677
- seoyoung-kang/CVE-2024-53677
- NKozl/Kozlitsky_Nikita_DZ_10
- ctfsec/CVE-2024-53677