U.S. Flag Official website of the Department of Homeland Security

Apache Releases Security Update for Apache Struts 2

Original release date: August 22, 2018 | Last revised: September 04, 2018

The Apache Software Foundation has released a security update to address a vulnerability in Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16. A remote attacker could exploit this vulnerability to take control of an affected system.

NCCIC encourages users and administrators to review Apache Security Bulletin S2-057 and apply the necessary update.

This product is provided subject to this Notification and this Privacy & Use policy.

Was this document helpful?  Yes  |  Somewhat  |  No

Back to Top