Forum Moderators: phranque

Message Too Old, No Replies

Apache Struts: Possible Remote Code Execution

         

engine

6:00 pm on Mar 20, 2017 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Time to update to Apache Struts V 2.3.32 or 2.5.10.1 to avoid a remote code execution attack.

Solution

If you are using Jakarta based file upload Multipart parser, upgrade to Apache Struts version 2.3.32 or 2.5.10.1. You can also switch to a different implementation of the Multipart parser. Apache Struts: Possible Remote Code Execution [cwiki.apache.org]

phranque

11:36 pm on Mar 29, 2017 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



discussion of a specific site's solutions/workarounds in this thread in the Apache Web Server forum:
latest Apache struts security issue [webmasterworld.com]