GHSA-43mq-6xmg-29vm · Severity: critical · Ecosystem: maven — Apache Struts file upload logic is flawed
File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. This issue affects Apache Struts: from 2.0.0 before 6.4.0. Users are recommended to upgrade to version 6.4.0 at least and migrate to the new file upload mechanism https://struts.apache.org/core-developers/file-upload . If you are not using an old file upload logic based on FileuploadInterceptor your application is safe. You can find more details in https://cwiki.apache.org/confluence/display/WW/S2-067
Conclusion & alert: CVE-2024-53677 is rated High Risk (72.7/100): CVSS Critical severity, with high exploitation likelihood (EPSS 93.16%, 100th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-25 | 93.34% | 93.16% | -0.18% |
| 2 | 2026-05-23 | 92.28% | 93.34% | +1.07% |
| 3 | 2026-05-22 | — | 92.28% | — |
Full EPSS history (57 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.5 | 4.0 | CRITICAL |
|
— | — | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
GHSA-43mq-6xmg-29vm · Severity: critical · Ecosystem: maven — Apache Struts file upload logic is flawed
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
critical | — | https://access.redhat.com/security/cve/CVE-2024-53677 |
suse
|
high | — | https://www.suse.com/security/cve/CVE-2024-53677/ |
| URL | Tags |
|---|---|
| https://cwiki.apache.org/confluence/display/WW/S2-067 | Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20250103-0005/ | Third Party Advisory |