QID 731026
Date Published: 2023-12-14
QID 731026: Apache Struts2 Remote Code Execution (RCE) Vulnerability (S2-066) (Intrusive Check)
Apache Struts is an open-source Model-View-Controller (MVC) framework for creating elegant, modern Java web applications.
An unauthenticated, remote attacker could exploit this vulnerability by manipulating file upload parameters to enable a path traversal condition. Uploading a malicious file by leveraging this vulnerability could lead to execution of malicious code on the targeted system.
Affected Software:
Struts 2.0.0 - Struts 2.3.37 (EOL)
Struts 2.5.0 - Struts 2.5.32
Struts 6.0.0 - Struts 6.3.0
QID Detection Logic (Unauthenticated):
This is an intrusive detection. This QID tries to upload a file 'qualystest.txt' to a vulnerable Apache Struts installation. To upload the file this QID sends an HTTP POST request to the 'upload.action' endpoint. By default Apache Struts stores the file temporarily and deletes it seconds after.
Note: This QID can check limited number of directories to test the file upload vulnerability. Customers are advised to search and remove the qualystest.txt file after scanning.
Successful exploitation allows an unauthenticated, remote attacker to execute arbitrary code on the targeted system.
CVEs related to QID 731026
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| S2-066 |
|