News: 1703167993

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Four in five Apache Struts 2 downloads are for versions featuring critical flaw

(2023/12/21)


Security vendor Sonatype believes developers are failing to address the critical remote code execution (RCE) vulnerability in the Apache Struts 2 framework, based on recent downloads of the code.

The vulnerability, tracked as CVE-2023-50164, is rated 9.8 out of 10 in terms of CVSS severity. It is a logic bug in the framework's file upload feature: if an application uses Struts 2 to allow users to upload files to a server, those folks can [1]abuse the vulnerability to save documents where they shouldn't be allowed to on that remote machine. Thus someone could, for instance, use the flaw to upload a webshell script to a web server, and access it to take control of or get a foothold on that system.

The consequences of successful exploitation could be hugely damaging: think data theft, malware infections, network intrusion, and that sort of thing.

[2]

The fix is simple: use versions of Struts that have been fixed.

[3]

[4]

Yet researchers at Sonatype, which operates the [5]Maven Central repository of open source software, has found that between the December 7 [6]disclosure of the flaw and December 18, around 80 percent of Struts downloads from that code silo were for versions that remain vulnerable to CVE-2023-50164.

That figure, the supplier asserts, is much worse than the adoption of the fixed version of Log4j in 2021 over a comparable timeframe.

[7]

The low download rate for safe cuts of Struts comes despite the [8]release of proof of concept (PoC) exploit code that prompted [9]government cyber-advisory services to call for rapid patching of the vulnerability.

Various [10]sources [11]confirmed the vulnerability was [12]under active exploitation as of December 13, although many attempts weren't valid since they weren't targeting endpoints with file upload functionality.

Regardless, many industry experts were quick to reaffirm the recommended guidance – which was to upgrade to the latest version of Struts 2 as soon as possible – but noted there was a list of preconditions that had to be met in order for an attack to be successful.

[13]SSH shaken, not stirred by Terrapin vulnerability

[14]Before you go away for Xmas: You've patched that critical Perforce Server hole, right?

[15]NKabuse backdoor harnesses blockchain brawn to hit several architectures

[16]Two years on, 1 in 4 apps still vulnerable to Log4Shell

"We believe that in most scenarios … most instances of exploitation of CVE-2023-50164 will be more one-off custom attacks against impacted applications meeting the required preconditions versus indiscriminate mass-exploitation attempts," noted Praetorian's researchers, whose [17]write-up nicely explains the constraints on real-world exploitation.

"However, while the risk of exploitation is much lower than prior vulnerabilities in Apache Struts, we still recommend that application developers running the impacted version of Apache Struts promptly upload to the latest version even in scenarios where the necessary preconditions for exploitability are unmet."

[18]

The researchers went on to point out that another factor hampering successful exploitation is the difficulty involved with scanning for vulnerable endpoints – again owing to the number of preconditions and the requirement for file upload functionality.

Despite the low likelihood of exploitation, Ilkka Turunen, field CTO at Sonatype, [19]argued there are factors at play that make the vulnerability's potential exploitation worth serious consideration.

If an attacker were to find an exploitable endpoint, or a collection of them, the attack is easily automatable. There is also no shortage of potential targets on the web if an attacker is reliably able to scan for vulnerable targets – given the wide use of Struts 2, and lower staffing levels at organizations often delay security upgrades and attack detection.

"As we navigate the holiday season, the urgency to address the Struts 2 vulnerability should be a high priority," he blogged. "The potential for remote code execution, reminiscent of the compromise that affected Equifax, underscores the need for swift action.

"While not as severe as some high-profile cases like log4j two years ago, these incidents serve as a reminder that open source, like any technology, requires vigilant maintenance. So, catalog your software and know your components. Additionally, create software bills of materials and scan for struts2-core." ®

Get our [20]Tech Resources



[1] https://www.trendmicro.com/en_us/research/23/l/decoding-cve-2023-50164--unveiling-the-apache-struts-file-upload.html

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZYRvOxh0vpRzNWX4mDQnPAAAAUA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZYRvOxh0vpRzNWX4mDQnPAAAAUA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZYRvOxh0vpRzNWX4mDQnPAAAAUA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://central.sonatype.com/

[6] https://nvd.nist.gov/vuln/detail/CVE-2023-50164

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZYRvOxh0vpRzNWX4mDQnPAAAAUA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://github.com/jakabakos/CVE-2023-50164-Apache-Struts-RCE

[9] https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/critical-vulnerability-in-popular-java-framework-apache-struts2

[10] https://cyberplace.social/@GossiTheDog/111574229161610139

[11] https://twitter.com/Shadowserver/status/1734919288257974380

[12] https://digital.nhs.uk/cyber-alerts/2023/cc-4423

[13] https://www.theregister.com/2023/12/20/terrapin_attack_ssh/

[14] https://www.theregister.com/2023/12/19/microsoft_warns_patch_critical_perforce/

[15] https://www.theregister.com/2023/12/15/nkabuse_blockchain_backdoor_botnet/

[16] https://www.theregister.com/2023/12/11/log4j_vulnerabilities/

[17] https://www.praetorian.com/blog/cve-2023-50164-apache-struts-file-upload-vulnerability/

[18] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZYRvOxh0vpRzNWX4mDQnPAAAAUA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[19] https://blog.sonatype.com/struts2-cve-2023-50164-by-the-numbers

[20] https://whitepapers.theregister.com/



So…..

Rich 2

Why didn’t they take the faulty versions of the code off the server so it couldn’t be downloaded?

Is it me????

Re: So…..

b0llchit

That may not be possible without severely breaking your source if you do builds from (a copy of) the source repository and use tags/branches or local hacks. These are cases where you need explicit action.

However, for pre-compiled builds, which apparently are the problem case here,... Well, because automated idiocracy is evolutionary predetermined?

But seriously, it is obvious that any pre-compiled version should be "unavailable" from the stream, but historically available by other means.

F. Frederick Skitty

Struts is very much a legacy technology in the Java world, so I expect it's being used in old projects where the developers are reluctant to change even a library version for fear of breaking things. The last project I used Struts on was in 2006, at which point it was already falling out of favour thanks to the rise of the Spring framework. Although it could be used with Spring, that framework's own MVC library was much easier to work with. That was also a time when unit testing was still a struggle to enforce on projects - I recall many frustrating meetings with project managers and stakeholders where they saw automated tests as a waste of effort. Classic comment I heard repeatedly was "if you were a competent programmer your code wouldn't need tests".

JamesTGrant

Totally fair point - but I’ve yet to meet a competent programmer, only human ones.

David 132

Someone really needs to come up with a language or framework named “Competent”, so that we get a lot more Competent Developers.

Wad some power the giftie gie us
To see oursels as others see us.
-- R. Burns