Bug 2253938 (CVE-2023-50164)

Summary: CVE-2023-50164 Struts: File upload component had a directory traversal vulnerability
Product: [Other] Security Response Reporter: Avinash Hanwate <ahanwate>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: urgent Docs Contact:
Priority: urgent    
Version: unspecifiedCC: adupliak, aileenc, anstephe, ant, anujha, aschwart, asoldano, aszczucz, ataylor, avibelli, bbaranow, bgeorges, bmaxwell, boliveir, brian.stansberry, bstansbe, ccranfor, cescoffi, chazlett, chfoley, clement.escoffier, cmiranda, cmoulliard, csutherl, dandread, darran.lofthouse, dbruscin, dhanak, dkreling, dlofthou, dosoudil, drichtar, drosa, dsimansk, dsoumis, ehugonne, fmariani, fmongiar, gmalinko, gsmet, ibek, istudens, ivassile, iweiss, janstey, jclere, jmartisk, jnethert, jpechane, jpoth, jrokos, jwon, kingland, kvanderr, kverlaen, lthon, manderse, matzew, max.andersen, mmadzin, mnovotny, mosmerov, mposolda, msochure, mstefank, msvehla, mulliken, nwallace, olubyans, pberan, pbizzarr, pcongius, pdelbell, pdrozd, peholase, pesilva, pgallagh, pierdipi, pjindal, plodge, pmackay, probinso, pskopek, rguimara, rhuss, rjohnson, rkieley, rmartinc, rmaucher, rowaters, rruss, rstancel, rstepani, rsvoboda, saroy, sausingh, sbiarozk, smaestri, ssilvert, sthorger, swoodman, szappis, tcunning, thjenkin, tom.jenkinson, tqvarnst, vdosoudi, vmuzikar, yfang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Struts 2.5.33, Struts 6.3.0.2 Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in Apache Struts. Affected versions of this package are vulnerable to Remote Code Execution (RCE) via manipulation of file upload parameters that enable path traversal. Under certain conditions, uploading a malicious file is possible, which may then be executed on the server.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2253939    

Description Avinash Hanwate 2023-12-11 06:03:58 UTC
An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue.

https://lists.apache.org/thread/yh09b3fkf6vz5d6jdgrlvmg60lfwtqhj
https://struts.apache.org/
https://www.cve.org/CVERecord?id=CVE-2023-50164