Hi,
According to CVE-2023-50164, Apache Struts has a Remote Code Execution vulnerability, present in version 2.5.32 of their library.
For more details see the following:
- https://nvd.nist.gov/vuln/detail/CVE-2023-50164
- https://cwiki.apache.org/confluence/display/WW/s2-066
We have conducted a security scan of our systems which has detected Apache Struts 2.5.32 JAR files in Crowd Server 5.2.1.
Our question is simple, is Atlassian Crowd (Server Edition) vulnerable to CVE-2023-50164? If it is, when will a fix be released?
Thank you to anyone who responds,
Adam
This details a patched 2.5.33 drop-in-replacement:
https://lists.apache.org/thread/yh09b3fkf6vz5d6jdgrlvmg60lfwtqhj
Obviously an official update from Atlassian would be best but this can make do until then as I suspect the holidays are going to delay vendor responses to this CVE.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.