![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEifWtfvyGPk0Wjzm_dUCKjDLHpNP6ms8AXQvnBXyooM80ArlGYC5GRagg1FsNXpgc6EoaF56tI-KiiZcJFJcDKUYa2IWN9nL8Hv1nYjVw-NqYh4rm7jECqq5HLzJ89y6iGe3UYXBFP2ZMrjzjw9triAbtZh78JGcI3huoTPqs8dALP2hK41gh6GJgg2VPme/s1600/apache.jpg)
Apache has released a security advisory warning of a critical security flaw in the Struts 2 open-source web application framework that could result in remote code execution.
Tracked as CVE-2023-50164, the vulnerability is rooted in a flawed “file upload logic” that could enable unauthorized path traversal and could be exploited under the circumstances to upload a malicious file
Source:: The Hackers News