CVE-2023-50164
07.12.2023, 09:15
An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater tofix this issue.Enginsight
Vendor | Product | Version |
---|---|---|
apache | struts | 2.0.0 ≤ 𝑥 < 2.5.33 |
apache | struts | 6.0.0 ≤ 𝑥 < 6.3.0.2 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References