Apache Releases Security Advisory for Apache Struts
The Apache Software Foundation has released an advisory to address a vulnerable commons-fileupload library used in Apache Struts. A remote attacker could exploit this vulnerability to take control of an affected system.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
The Apache Software Foundation has released an advisory to address a vulnerable commons-fileupload library used in Apache Struts. A remote attacker could exploit this vulnerability to take control of an affected system.
Affected platforms
The following platforms are known to be affected:
Threat details
Remediation steps
| Type | Step |
|---|---|
|
Users and administrators are encouraged to review the Apache security advisory for CVE-2016-1000031 and upgrade to the latest released version of Commons FileUpload library, which is currently 1.3.3. |
CVE Vulnerabilities
Last edited: 17 February 2020 12:37 pm