Feed/CVE-2024-53677
CVE-2024-53677CRITICALCVSS 9.8

CVE-2024-53677

Published Dec 11, 2024·Updated Jun 17, 2026

NVD Description

File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. This issue affects Apache Struts: from 2.0.0 before 6.4.0. Users are recommended to upgrade to version 6.4.0 at least and migrate to the new file upload mechanism https://struts.apache.org/core-developers/file-upload . If you are not using an old file upload logic based on FileuploadInterceptor your application is safe. You can find more details in  https://cwiki.apache.org/confluence/display/WW/S2-067

Public Exploits & PoCs13 found

PoC: CVE-2024-53677-Docker

A Docker-based environment to reproduce the CVE-2024-53677 vulnerability in Apache Struts 2.

2

PoC: CVE-2024-53677

Vulnerable Environment and Exploit for CVE-2024-53677

1

PoC: CVE-2024-53677-S2-067

A critical vulnerability, CVE-2024-53677, has been identified in the popular Apache Struts framework, potentially allowing attackers to execute arbitrary code remotely. This vulnerability arises from flaws in the file upload logic, which can be exploited to perform path traversal and malicious file uploads.

1

PoC: CVE-2024-53677

Proof of concept exploit for CVE-2024-53677 - Apache Struts file upload path traversal vulnerability leading to Remote Code Execution

PoC: CVE-2024-53677-Analysis

CVE-2024-53677 취약점 분석 보고서

PoC: CVE-2024-53677

CVE-2024-53677 관련 컨설턴트용 툴 개발

PoC: CVE-2024-53677-POC

a proof of concept of CVE-2024-53677

PoC: CVE-2024-53677

CVE-2024-53677

PoC: CVE-2024-53677-Exploitation

Apache Struts CVE-2024-53677 Exploitation

PoC: CVE-2024-53677

Proof-of-Concept for CVE-2024-46538

PoC: VM-CVE-2024-53677

Struts Vulnerability - CVE-2024-53677

PoC: CVE-2024-53677-S2-067

A critical vulnerability, CVE-2024-53677, has been identified in the popular Apache Struts framework, potentially allowing attackers to execute arbitrary code remotely. This vulnerability arises from flaws in the file upload logic, which can be exploited to perform path traversal and malicious file uploads.

PoC: s2-067-CVE-2024-53677

s2-067(CVE-2024-53677)

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free