Description |
Apache Struts 2 is an open-source web application framework for developing Java web applications.
CVE-2023-50164 and CVE-2024-53677 are file upload path traversal vulnerabilities which allows attackers to path traverse, upload malicious files and perform remote code execution (RCE). |
|||||||||
CVE ID |
CVE-2024-53677 (https://nvd.nist.gov/vuln/detail/CVE-2024-53677) |
|||||||||
NDR Cloud Detection Rule |
FortiNDR Cloud v2024.11+
|
|||||||||
Playbook |
N/A |
|||||||||
Threat Hunting |
FortiNDR Cloud users can use the following IOCs from Fortinet to hunt for “Apache Struts 2 RCE Attack” related activities IOC source: https://www.fortiguard.com/outbreak-ioc?tag=Apache%20Struts%202%20RCE All IOCs listed above have been added to Threat Intelligence Intel |
|||||||||
Suricata Coverage |
Customers can create custom investigation/detections using the Suricata signatures below: 2058337 -> ET WEB_SPECIFIC_APPS Apache Struts2 Path Traversal Attempt Inbound M1 (CVE-2024-53677) 2049669 -> ET WEB_SPECIFIC_APPS Apache Struts2 Possible uploadFileName Directory Traversal Attempt (CVE-2023-50164) - uploadFileName Parameter M1 2049667 -> ET WEB_SPECIFIC_APPS Apache Struts2 uploadFileName Directory Traversal Attempt (CVE-2023-50164) M1 2058341 -> ET WEB_SPECIFIC_APPS Apache Struts2 Path Traversal Attempt Inbound M2 (CVE-2024-53677) |
|||||||||
Other Fortinet Products |
For more details regarding mitigating the vulnerability by utilizing Fortinet products, please refer to |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.