Loading HuntDB...

Apache Struts Remote Code Execution Vulnerability

Added Nov. 3, 2021 Due May 3, 2022 CVE-2017-5638
Overdue Apache / Struts Known Ransomware Use CWE-20

Description

Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.

Required Action

Apply updates per vendor instructions.

References

Additional Information

Catalog Version
2025.01.24
Catalog Released
Jan. 24, 2025
Days Until Due
0 days
Last Updated
7 months, 3 weeks ago