FortiNDRCloud
SaaS based NDR solution providing 365 days data retention, along with Technical Success Manager
kcheung
Staff
Staff
Article Id 369493
Description

Apache Struts 2 is an open-source web application framework for developing Java web applications.

 

CVE-2023-50164 and CVE-2024-53677 are file upload path traversal vulnerabilities which allows attackers to path traverse, upload malicious files and perform remote code execution (RCE).

CVE ID

CVE-2024-53677 (https://nvd.nist.gov/vuln/detail/CVE-2024-53677)
CVE-2023-50164 (https://nvd.nist.gov/vuln/detail/CVE-2023-50164)

NDR Cloud Detection Rule

FortiNDR Cloud v2024.11+

Detection Rule Name

Category

Primary MITRE ID

FortiGuard Outbreak Alert: Apache Struts 2 Remote Code Execution - CVE-2024-53677

Attack:Exploitation

T1190 - Exploit Public-Facing Application

FortiGuard Outbreak Alert: CVE-2023-50164 Apache Struts2 File Upload via HTTP POST Request

Attack:Exploitation

T1190 - Exploit Public-Facing Application

Playbook

N/A

Threat Hunting

FortiNDR Cloud users can use the following IOCs from Fortinet to hunt for “Apache Struts 2 RCE Attack” related activities

IOC source: https://www.fortiguard.com/outbreak-ioc?tag=Apache%20Struts%202%20RCE

All IOCs listed above have been added to Threat Intelligence Intel

Suricata Coverage

Customers can create custom investigation/detections using the Suricata signatures below:

2058337 -> ET WEB_SPECIFIC_APPS Apache Struts2 Path Traversal Attempt Inbound M1 (CVE-2024-53677)

2049669 -> ET WEB_SPECIFIC_APPS Apache Struts2 Possible uploadFileName Directory Traversal Attempt (CVE-2023-50164) - uploadFileName Parameter M1

2049667 -> ET WEB_SPECIFIC_APPS Apache Struts2 uploadFileName Directory Traversal Attempt (CVE-2023-50164) M1

2058341 -> ET WEB_SPECIFIC_APPS Apache Struts2 Path Traversal Attempt Inbound M2 (CVE-2024-53677)

Other Fortinet Products

For more details regarding mitigating the vulnerability by utilizing Fortinet products, please refer to
https://www.fortiguard.com/outbreak-alert/apache-struts-2-rce

Contributors