Hi,
According to CVE-2023-50164, Apache Struts has a Remote Code Execution vulnerability, present in version 2.5.32 of their library.
For more details see the following:
- https://nvd.nist.gov/vuln/detail/CVE-2023-50164
- https://cwiki.apache.org/confluence/display/WW/s2-066
We have conducted a security scan of our systems which has detected Apache Struts 2.5.32 JAR files in Crowd Server 5.2.1.
Our question is simple, is Atlassian Crowd (Server Edition) vulnerable to CVE-2023-50164? If it is, when will a fix be released?
Thank you to anyone who responds,
Adam
This details a patched 2.5.33 drop-in-replacement:
https://lists.apache.org/thread/yh09b3fkf6vz5d6jdgrlvmg60lfwtqhj
Obviously an official update from Atlassian would be best but this can make do until then as I suspect the holidays are going to delay vendor responses to this CVE.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.