Skip to main content

Struts vulnerabilities

1 published alerts for Apache Struts.

Actively exploited (KEV)Ransomware

CVE-2017-5638

Apache Struts Remote Code Execution Vulnerability

Apache Struts is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-5638). Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.