Struts 2.3 Vulnerable to Two Year old File Upload Flaw, (Mon, Nov 5th)

Apache today released an advisory, urging users who run Apache Struts 2.3.x to update the commons-fileupload component [1]. Struts 2.3.x uses by default the old 1.3.2 version of commons-fileupload. In November of 2016, a deserialization vulnerability was disclosed and patched in commons-fileupload [2]. The vulnerability can lead to arbitrary remote code execution.

Article Link: https://isc.sans.edu/diary/rss/24278