CVE-2024-53677

CRITICAL EXPLOITED

Apache Struts < 6.4.0 - Unrestricted File Upload

Title source: rule

Description

File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. This issue affects Apache Struts: from 2.0.0 before 6.4.0. Users are recommended to upgrade to version 6.4.0 at least and migrate to the new file upload mechanism https://struts.apache.org/core-developers/file-upload . If you are not using an old file upload logic based on FileuploadInterceptor your application is safe. You can find more details in  https://cwiki.apache.org/confluence/display/WW/S2-067

Exploits (20)

nomisec WORKING POC 94 stars
by TAM-K592 · poc
https://github.com/TAM-K592/CVE-2024-53677-S2-067
github WORKING POC 40 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/Struts2(CVE-2024-53677,S2-067).py
nomisec WORKING POC 15 stars
by EQSTLab · remote
https://github.com/EQSTLab/CVE-2024-53677
nomisec WORKING POC 9 stars
by cloudwafs · poc
https://github.com/cloudwafs/s2-067-CVE-2024-53677
nomisec WORKING POC 3 stars
by c4oocO · poc
https://github.com/c4oocO/CVE-2024-53677-Docker
nomisec WORKING POC 3 stars
by shishirghimir · poc
https://github.com/shishirghimir/CVE-2024-53677-Exploit
nomisec WORKING POC 3 stars
by SeanRickerd · remote
https://github.com/SeanRickerd/CVE-2024-53677
nomisec WORKING POC 3 stars
by yangyanglo · remote
https://github.com/yangyanglo/CVE-2024-53677
nomisec WORKING POC 2 stars
by dustblessnotdust · remote
https://github.com/dustblessnotdust/CVE-2024-53677-S2-067-thread
nomisec WORKING POC 2 stars
by r007sec · remote
https://github.com/r007sec/CVE-2024-53677
nomisec WORKING POC 1 stars
by Cythonic1 · remote
https://github.com/Cythonic1/CVE-2024-53677-POC
nomisec WORKING POC 1 stars
by punitdarji · remote
https://github.com/punitdarji/Apache-struts-cve-2024-53677
nomisec WORKING POC
by 0xPThree · remote
https://github.com/0xPThree/struts_cve-2024-53677
nomisec WRITEUP
by hopsypopsy8 · remote
https://github.com/hopsypopsy8/CVE-2024-53677-Exploitation
nomisec WORKING POC
by MartinxMax · remote
https://github.com/MartinxMax/CVE-2024-53677
nomisec WORKING POC
by 0xdeviner · poc
https://github.com/0xdeviner/CVE-2024-53677
nomisec WORKING POC
by seoyoung-kang · remote
https://github.com/seoyoung-kang/CVE-2024-53677

Scores

CVSS v3 9.8
EPSS 0.9305
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

VulnCheck KEV 2024-12-15

Classification

CWE
CWE-434
Status published

Affected Products (2)

apache/struts < 6.4.0
org.apache.struts/struts2-core < 6.4.0Maven

Timeline

Published Dec 11, 2024
Tracked Since Feb 18, 2026