Researchers have found a critical remote code execution vulnerability in Apache Struts REST Plugin. Clients using Apache Struts versions 2.1.2 to 2.3.33, or 2.5 to 2.5.12 are highly encouraged to patch immediately.
eSentire highly recommends upgrading to either Struts 2.3.34 or Struts 2.5.13 to mitigate this threat.
This vulnerability is addressed by ensuring your Struts version has been updated to version 2.3.34 or 2.5.13.
Public exploits have been reported, therefore patching vulnerable systems should be treated as priority. Apache has released a security bulletin with further details on this vulnerability, as well as solutions and workarounds. Read the full bulletin here: