CISCO-SA-20181107-STRUTS-COMMONS-FILEUPLOAD
On November 5, 2018, the Apache Struts Team released a security announcement urging an upgrade of the Commons FileUpload library to version 1.3.3 on systems using Struts 2.3.36 or earlier releases. Systems using earlier versions of this library may be exposed to attacks that could allow execution of arbitrary code or modifications of files on the system. The issue is caused by a previously reported vulnerability of the Apache Commons FileUpload library, assigned to CVE-2016-1000031. The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this vulnerability by submitting crafted data to an affected system. A successful exploit could allow the attacker to execute arbitrary code or manipulate files on the targeted system.
Risk Scores
Timeline
- Nov 7, 2018 CVE Published
- Feb 7, 2019 CVE Updated
References
- https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html url
- https://bst.cloudapps.cisco.com/bugsearch/bug/BUGID url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn18895 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn44132 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn18924 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn18910 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn19758 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn20600 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn18956 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn18957 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn18959 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn18952 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn18888 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn18887 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn18954 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn18928 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn22305 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn19865 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn22310 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvn18884 url
…and 22 more