CERT mailing list archives

Apache Releases Security Advisory for Apache Struts


From: "US-CERT" <US-CERT () ncas us-cert gov>
Date: Mon, 05 Nov 2018 14:17:32 -0600

U.S. Department of Homeland Security US-CERT

National Cyber Awareness System:



Apache Releases Security Advisory for Apache Struts [ 
https://www.us-cert.gov/ncas/current-activity/2018/11/05/Apache-Releases-Security-Advisory-Apache-Struts ] 11/05/2018 
02:34 PM EST 
Original release date: November 05, 2018

The Apache Software Foundation has released an advisory to address a vulnerable commons-fileupload library used in 
Apache Struts versions 2.3.36 and prior. A remote attacker could exploit this vulnerability to take control of an 
affected system. Struts versions from 2.5.12 are not affected.

NCCIC encourages users and administrators of Apache Struts versions 2.3.36 and prior to review the Apache security 
advisory for CVE-2016-1000031 [ 
http://mail-archives.us.apache.org/mod_mbox/www-announce/201811.mbox/%3CCAMopvkMo8WiP%3DfqVQuZ1Fyx%3D6CGz0Epzfe0gG5XAqP1wdJCoBQ%40mail.gmail.com%3E
 ] and upgrade to the latest released version of Commons FileUpload library, which is currently 1.3.3.

________________________________________________________________________

This product is provided subject to this Notification [ http://www.us-cert.gov/privacy/notification ] and this Privacy 
& Use [ http://www.us-cert.gov/privacy/ ] policy.

body { font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight: normal; font-style: normal; color: 
#333333; } ________________________________________________________________________

A copy of this publication is available at www.us-cert.gov [ https://www.us-cert.gov ]. If you need help or have 
questions, please send an email to info () us-cert gov. Do not reply to this message since this email was sent from a 
notification-only address that is not monitored. To ensure you receive future US-CERT products, please add US-CERT () 
ncas us-cert gov to your address book. 

OTHER RESOURCES: Contact Us [ http://www.us-cert.gov/contact-us/ ] | Security Publications [ 
http://www.us-cert.gov/security-publications ] | Alerts and Tips [ http://www.us-cert.gov/ncas ] | Related Resources [ 
http://www.us-cert.gov/related-resources ]  

STAY CONNECTED: Sign up for email updates [ http://public.govdelivery.com/accounts/USDHSUSCERT/subscriber/new ] 


Current thread: