Vulnerability record · CVE-2024-53677 · published 11 December 2024
CVE-2024-53677: Apache Struts file upload path traversal leading to RCE
Apache · Struts
The file upload logic in Apache Struts is flawed, allowing an attacker to manipulate upload parameters to traverse paths and, under some circumstances, upload a malicious file that can be executed. It affects Struts from 2.0.0 before 6.4.0, and applications using the legacy FileuploadInterceptor-based upload mechanism are exposed. Because successful exploitation can yield remote code execution, this is a serious risk for unpatched Struts deployments.
Description
File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. This issue affects Apache Struts: from 2.0.0 before 6.4.0. Users are recommended to upgrade to version 6.4.0 at least and migrate to the new file upload mechanism https://struts.apache.org/core-developers/file-upload . If you are not using an old file upload logic based on FileuploadInterceptor your application is safe. You can find more details in https://cwiki.apache.org/confluence/display/WW/S2-067
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:
Automated analysis
critical priorityCVSS 4.0 base score is 9.5 critical with network reachability, no privileges or user interaction required, and remote code execution potential, while EPSS is 0.70 at the 99.3rd percentile.
What it is
The file upload logic in Apache Struts is flawed, allowing an attacker to manipulate upload parameters to traverse paths and, under some circumstances, upload a malicious file that can be executed. It affects Struts from 2.0.0 before 6.4.0, and applications using the legacy FileuploadInterceptor-based upload mechanism are exposed. Because successful exploitation can yield remote code execution, this is a serious risk for unpatched Struts deployments.
Impact
An attacker can write files outside the intended upload directory and, in the right conditions, execute a malicious uploaded file, gaining remote code execution on the server. That typically means full control of the application process and its data.
Attack surface
The flaw is reached over the network through the file upload handling of a Struts application; the CVSS 4.0 vector indicates no privileges and no user interaction are required. Only applications using the old FileuploadInterceptor-based upload logic are affected, per the vendor advisory.
Exploitation
The record shows no CISA KEV listing and no reference tags indicating a public exploit, but EPSS is very high at 0.70143 (99.3rd percentile), suggesting elevated likelihood of exploitation activity. No ransomware group usage is documented in this record.
What to do
- Upgrade Apache Struts to version 6.4.0 or later.
- Migrate applications to the new Struts file upload mechanism and stop using the legacy FileuploadInterceptor-based logic.
- If immediate upgrade is not possible, restrict or disable legacy file upload endpoints and apply strict upload path validation.
- Run the application with least privilege and ensure uploaded files cannot be executed from the upload directory.
- Monitor vendor and third-party advisories for updated guidance.
Detection
- Review web and application logs for file upload requests containing path traversal sequences such as ../ or encoded variants.
- Alert on files created outside expected upload directories, especially executable extensions such as .jsp, .jspx, or .war.
- Monitor for unexpected child processes spawned by the Java application server, which may indicate post-exploitation execution.
- Audit Struts configurations to identify applications still using the legacy FileuploadInterceptor upload mechanism.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://cwiki.apache.org/confluence/display/WW/S2-067 | Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20250103-0005/ | Third Party Advisory |
Track CVE-2024-53677 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-53677), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.