CISCO-SA-20181107-STRUTS-COMMONS-FILEUPLOAD
On November 5, 2018, the Apache Struts Team released a security announcement urging an upgrade of the Commons FileUpload library to version 1.3.3 on systems using Struts 2.3.36 or earlier releases. Systems using earlier versions of this library may be exposed to attacks that could allow execution of arbitrary code or modifications of files on the system. The issue is caused by a previously reported vulnerability of the Apache Commons FileUpload library, assigned to CVE-2016-1000031. The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this vulnerability by submitting crafted data to an affected system. A successful exploit could allow the attacker to execute arbitrary code or manipulate files on the targeted system.
Risk Scores
Timeline
- Nov 7, 2018 CVE Published
- Feb 7, 2019 CVE Updated
References
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-struts-commons-fileupload advisory
- https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html url
- https://bst.cloudapps.cisco.com/bugsearch/bug/BUGID url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn22343 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn18895 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn18901 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn17524 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn18934 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn44132 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn18919 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn18917 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn18924 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn18913 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn18910 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn22307 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn19758 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn20600 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn18956 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn18957 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn22344 url
…and 22 more