CVE-2023-50164
CVSS V2 None
CVSS V3 None
Description
An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution.
Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue.
Overview
- CVE ID
- CVE-2023-50164
- Assigner
- apache
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-12-07T08:49:19.853Z
- Last Modified Date
- 2023-12-12T09:26:34.588Z
Weakness Enumerations
References
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-50164 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-50164 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 18:09:24 | Added to TrackCVE |