QID 150774
Date Published: 2023-12-19
QID 150774: Apache Struts2 Remote Code Execution (RCE) Vulnerability (CVE-2023-50164) (Intrusive Check)
Apache Struts is a free, open-source, MVC framework for creating elegant, modern Java web applications.
In affected versions of Apache Struts 2, an attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution (RCE).
Affected Versions:
Apache Struts 2.0.0 - 2.3.37(EOL)
Apache Struts 2.5.0 - 2.5.32
Apache Struts 6.0.0 - 6.3.0
QID Detection Logic (Unauthenticated):
This QID sends HTTP POST request to ".action" endpoint and tries to upload 'Qualyswas.txt' and 'Qualyswas.jsp' file using Path traversal payloads such as "../../" "../webapps/" and "../".
NOTE: This is an intrusive detection which uploads files on vulnerable instance of Apache Struts. Once the scanning is completed, customers are advised to search and remove 'Qualyswas.txt' and 'Qualyswas.jsp' from the Application server.
Successful exploitation of this vulnerability could allow a remote attacker to upload malicious files and execute arbitrary code on the target system.
CVEs related to QID 150774
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| S2-066 |
|