#struts2
🎅 & #threatintel: We at GreyNoise recently added a tag for Apache Struts2 CVE-2024-53677 regarding unauthenticated file upload attempts. Despite numerous reports of exploitation in the wild, we have not observed any beyond the originally published PoC.

viz.greynoise.io/tag...
1/2
December 18, 2024 at 9:26 PM
I'm having doubts about the information circulating around CVE-2024-53677 (the Apache Struts2 file upload vuln).
We're still digging into this but many POCs seem to be, not. We do see scanning for it, but exploitation.... TBD.
December 18, 2024 at 3:47 PM
Mais ou menos tbm né? Mesmo um iniciante tem que entregar valor... tem que botar task pra fora e completar card do JIRA. Essas tasks todas são feitas com framework.

Por exemplo, meu primeiro trampo fora da universidade a gente tinha que saber Struts2, JSPs, Hibernate.
October 26, 2024 at 4:21 PM
#Struts2 #jQuery Plugin version 3.3.2 provides now support for Trees with Checkboxes http://www.jgeppert.com/2012/07/struts2-jquery-plugin-
Struts2 jQuery Plugin 3.2.0 released
www.jgeppert.com
November 25, 2024 at 10:31 AM
Struts JQuery Plugin ver 6.0.0 is out with full support for Struts 7.0.0 and Java 17!

#java #struts #jquery #plugin #release

github.com/struts-commu...
Release 6.0.0 · struts-community-plugins/struts2-jquery
What's Changed Upgrades to Struts 7 by @lukaszlenart in #597 Dependencies Update log4j2 monorepo to v2.24.3 by @renovate in #588 Update dependency org.junit.jupiter:junit-jupiter to v5.11.4 by @...
github.com
January 9, 2025 at 8:39 AM
My proglang journey:
1993: C++, perl, SQL: XWindows/Motif, Solaris/SunOS
1997: Add Windows, HP/UX
1999: Java, JSP, Servlets
2003: Add Struts 1, JSF
2005: Add Groovy: Struts2, WebWork
2013: Scala
2018: Python, Django, DRF (barely touched Vue)
2020: Javascript/Typescript; React
2021: Ruby, Rails
November 30, 2024 at 12:47 PM
jQuery UI Menu support with now released #Struts2 #jQuery Plugin 3.5.0 http://wp.me/phNXX-aX #java
jQuery UI Menu support with now released Struts2 jQuery Plugin 3.5.0
wp.me
November 25, 2024 at 10:33 AM
Apache Struts 2: un nuovo bug di sicurezza mette a rischio le applicazioni aziendali

📌 Link all'articolo : www.redhotcyber.com/post/apa...

#redhotcyber #news #cybersecurity #hacking #vulnerabilita #apache #struts2 #frameworkjava #sicurezzainformatica
January 12, 2026 at 9:38 AM
Just released a new version 1.1.0 of the #Struts2 #Cloud support plugin to easily run @TheApacheStruts based #microservices as #AWS #Serverless #Lambda method behind an API Gateway. Now it is based on the Struts2 support of the aws serverless project.

http://bit.ly/s2-cloud
GitHub - struts-community-plugins/struts2-cloud-support
Contribute to struts-community-plugins/struts2-cloud-support development by creating an account on GitHub.
bit.ly
November 25, 2024 at 10:54 AM
Try out the new #Struts2 #AWS #Lambda plugin! Now it is easy to run your @ApacheStruts application as #serverless #microservice lambda function behind an @awscloud #API gateway.

http://bit.ly/s2-cloud

#Java #CloudComputing #OpenSource
GitHub - struts-community-plugins/struts2-cloud-support
Contribute to struts-community-plugins/struts2-cloud-support development by creating an account on GitHub.
bit.ly
November 25, 2024 at 10:51 AM
Details: Assetnote disclosed three CVEs in AEM Forms—
• CVE-2025-49533: Insecure deserialization → RCE (CVSS 9.8)
• CVE-2025-54254: XXE → arbitrary file reads (CVSS 8.6)
• CVE-2025-54253: Struts2 devMode → unauthenticated RCE (CVSS 10.0)

#InfoSec #ThreatIntel
August 6, 2025 at 9:04 AM

Struts Bootstrap plugin ver 6.0.0 is out, with support for Struts 7.0.0 and Java 17! Enjoy!

#struts #bootstrap #plugin #release #java

github.com/struts-commu...
Release 6.0.0 · struts-community-plugins/struts2-bootstrap
What's Changed Upgrades to Struts 7 by @lukaszlenart in #353 Reconfigures renovate to keep 6.0.x branch up to date by @lukaszlenart in #357 Update log4j2 monorepo to v2.24.3 (release/5.0.x) by @re...
github.com
January 9, 2025 at 5:26 PM
Version 2.2.0 of #Struts2 #jQuery Plugin is now available. with support foe #jqueryui 1.8.2 and #jqgrid 3.6.5 http://cli.gs/QSq0S
November 25, 2024 at 10:07 AM
うわこれすごい話だ。

■【お知らせ】Apache Struts2の脆弱性(S2-067、CVE-2024-53677)において、クラウド型 WAF「Scutum」は2023年12月時点で対策済み | 脆弱性診断とクラウド型WAFのセキュアスカイ・テクノロジー(SST)
www.securesky-tech.com/2024/12/13/7...
【お知らせ】Apache Struts2の脆弱性(S2-067、CVE-2024-53677)において、クラウド型 WAF「Scutum」は2023年12月時点で対策済み | 脆弱性診断とクラウド型WAFのセキュアスカイ・テクノロジー(SST)
クラウド型WAFサービス「Scutum(スキュータム)」は、Apache Struts2の脆弱性(S2-067、CVE-2024-53677)を狙った攻撃について、前年2023年12月10日時点で、防御できる状態に更新済みです。
www.securesky-tech.com
December 13, 2024 at 5:32 AM
#aws #serverless now with support for #Struts2 is released. Thanks @sapessi for the support.

#lambda #cloud #apache #struts https://twitter.com/sapessi/status/1055202054879113216
November 25, 2024 at 10:54 AM
#Struts2 support in JetBrains IntelliJ #IDEA: Validator integration http://www.youtube.com/watch?v=S6RkrbedqTQ #apache #struts
Struts 2 support in JetBrains IntelliJ IDEA: Validator integration
www.youtube.com
November 25, 2024 at 10:28 AM
これを読んで「今更デシリアライズを独自実装してサーバサイドのリモートコード実行やらかすとか、いつからVercelはNext.jsについてWAFもりもりStruts2太郎へ進化()する可能性を許容し始めたのかなあ」という思いになっており…

https://x.com/bulkneets/status/2000007927428739284
December 19, 2025 at 9:07 AM
I saw it and CVE but I agree, especially if you have run a good amount of test and still have trouble finding exploits, now I don't use Struts2 just know about it, perhaps there is but for now I have to agree... don't lose sleep over it
December 18, 2024 at 9:08 PM
Es increíble lo confuso que se vuelve un JSP cuando se mezclan los conceptos de Struts2 y de la JSTL. Es verdad que pueden convivir porque uno se invoca con %{…} y otro con ${…},y sus alcances son diferentes. Pero me parece que mis compañeros no han estudiado todo lo que puede hacer Struts sin JSTL
November 11, 2024 at 1:10 PM
struts2の脆弱性はjavaのオブジェクトをごちゃごちゃって言えばそれまでなんだけど、古代の悪しき言語的慣習を複合的についてるのが面白いが、昨今面白いことを解説するとおこられたりとか政治的なやつが増えているため全員黙っている気がする
December 18, 2023 at 7:40 AM
Join us in the lab as we explore a day in the life of @remyhax.bsky.social as he navigates the path to uncovering the Remote Code Execution Vulnerability (CVE-2023-50164) in Apache Struts2. 🥼
A Day In The Life Of A GreyNoise Researcher: The Path To Understanding The Remote Code Execution Vul...
Discover what our amazing researcher Matthew Remacle uncovers as he investigates a new vulnerability in Apache Struts! This weakness enables attackers to remotely drop and call a web shell through a p...
www.greynoise.io
December 13, 2023 at 5:04 PM
JSON Deserialiser Unconstrained Resource Consumption Proof of Concept

Posted by Daniel Owens via Fulldisclosure on Aug 29On 26 October 2025 we published "Struts2 and Related Framework Array/Collection DoS", which was followed up on 07 March
2026 by "JSON Deserialiser Unconstrain…
#hackernews #news
JSON Deserialiser Unconstrained Resource Consumption Proof of Concept
Posted by Daniel Owens via Fulldisclosure on Aug 29On 26 October 2025 we published "Struts2 and Related Framework Array/Collection DoS", which was followed up on 07 March 2026 by "JSON Deserialiser Unconstrained Resource Consumption Quick Overview". Today we are publishing a proof of concept that we have been using for more than 15 years against Struts2, Newtonsoft JSON, JSON.org, and various other JSON parsers. We are publishing, in part, because of the theft of our...
seclists.org
August 31, 2026 at 12:56 AM
Copilot's hidden debug flag let attackers steal credentials via one click, per Ars Technica. LLM integration remains treated as a feature, not a privilege escalation risk. This is Struts2 RCE in prompt-injection form.
August 20, 2026 at 1:15 AM