Threat actors target Apache Struts 2 due to vulnerabilities in its code that can be exploited for unauthorized access to web applications.
Exploiting these vulnerabilities allows attackers to execute arbitrary code that could lead to full system compromise.
As Apache Struts 2 is widely used in web development, successful attacks can impact many applications, making it an attractive target for those seeking widespread exploits and data breaches.
Cybersecurity researchers at CYFIRMA Research recently discovered more than 1,718,898 Apache Struts 2 installations are open to RCE (Remote code execution) attacks.
The RCE flaw was tracked as “CVE-2023-50164” by security analysts, and this flaw enables threat actors to perform remote code execution and file upload attacks.
Compounding the problem are zero-day vulnerabilities like the MOVEit SQLi, Zimbra XSS, and 300+ such vulnerabilities that get discovered each month. Delays in fixing these vulnerabilities lead to compliance issues, these delay can be minimized with a unique feature on AppTrana that helps you to get “Zero vulnerability report” within 72 hours.
Flaw profile
Technical analysis
Apache Struts 2 faces a major threat with CVE-2023-50164, which lets attackers execute code and upload malicious files.
CYFIRMA researchers exposed the flaw’s severity and tied it to a file upload weakness in the framework, posing serious security risks.
Exploiting this critical RCE vulnerability endangers system integrity and confidentiality and opens doors to data breaches.
Security experts highlight the exploit’s reliance on HTTP parameter case sensitivity that enables the threat actors to manipulate the variables that are critical in nature.
However, the Apache team responds strategically to a vulnerability by introducing equalsIgnoreCase() method, countering case sensitivity manipulation in recent commits.
The enhancement aims to strengthen the Apache Struts against parameter pollution leading to path traversal exploits. The vulnerability in AbstractMultiPartRequest.java allows the persistence of path traversal payloads.
The concerns also involve handling of the oversized temporary files during uploads which could pose a serious persistence threat.
Apache introduced a crucial commitment to counter the risks, ‘Always delete uploaded file,’ this ensures consistent removal of temporary files and also blocks the avenues for persistent attacks.
The commitment reflects proactive measures to address security concerns. Besides this, the recent code changes also affirm Apache’s commitment to enhancing framework security.
Apply Apache Struts 2 updates as soon as possible to mitigate the “CVE-2023-50164” flaw. Boost defense with custom rules, file upload monitoring, and improved firewall settings. Make sure to act promptly to stop any unauthorized access and code execution.
Try Kelltron’s cost-effective penetration testing services to evaluate digital systems security. available.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…