安全研究

CVE-2023-50164 Apache Struts 文件上传路径穿越到 RCE:经典框架的老问题

#漏洞分析#代码审计#Web安全
铜橙色 Struts 文件上传路径被穿越到 Tomcat webapps 目录

Apache Struts 在 ActionSupport 处理文件上传时未严格校验上传路径,攻击者改一个 multipart 字段名,就能把 webshell 直接投到 Tomcat webapps 目录里——这是 Struts 在 2023 年又一次被『路径穿越到 RCE』的老戏码击中。

Unlock to view this content.