viz.greynoise.io/tag...
1/2
viz.greynoise.io/tag...
1/2
We're still digging into this but many POCs seem to be, not. We do see scanning for it, but exploitation.... TBD.
We're still digging into this but many POCs seem to be, not. We do see scanning for it, but exploitation.... TBD.
Por exemplo, meu primeiro trampo fora da universidade a gente tinha que saber Struts2, JSPs, Hibernate.
Por exemplo, meu primeiro trampo fora da universidade a gente tinha que saber Struts2, JSPs, Hibernate.
#java #struts #jquery #plugin #release
github.com/struts-commu...
1993: C++, perl, SQL: XWindows/Motif, Solaris/SunOS
1997: Add Windows, HP/UX
1999: Java, JSP, Servlets
2003: Add Struts 1, JSF
2005: Add Groovy: Struts2, WebWork
2013: Scala
2018: Python, Django, DRF (barely touched Vue)
2020: Javascript/Typescript; React
2021: Ruby, Rails
1993: C++, perl, SQL: XWindows/Motif, Solaris/SunOS
1997: Add Windows, HP/UX
1999: Java, JSP, Servlets
2003: Add Struts 1, JSF
2005: Add Groovy: Struts2, WebWork
2013: Scala
2018: Python, Django, DRF (barely touched Vue)
2020: Javascript/Typescript; React
2021: Ruby, Rails
#java #struts #jquery #plugin #release #webdev
github.com/struts-commu...
📌 Link all'articolo : www.redhotcyber.com/post/apa...
#redhotcyber #news #cybersecurity #hacking #vulnerabilita #apache #struts2 #frameworkjava #sicurezzainformatica
📌 Link all'articolo : www.redhotcyber.com/post/apa...
#redhotcyber #news #cybersecurity #hacking #vulnerabilita #apache #struts2 #frameworkjava #sicurezzainformatica
http://bit.ly/s2-cloud
http://bit.ly/s2-cloud
http://bit.ly/s2-cloud
#Java #CloudComputing #OpenSource
http://bit.ly/s2-cloud
#Java #CloudComputing #OpenSource
• CVE-2025-49533: Insecure deserialization → RCE (CVSS 9.8)
• CVE-2025-54254: XXE → arbitrary file reads (CVSS 8.6)
• CVE-2025-54253: Struts2 devMode → unauthenticated RCE (CVSS 10.0)
#InfoSec #ThreatIntel
• CVE-2025-49533: Insecure deserialization → RCE (CVSS 9.8)
• CVE-2025-54254: XXE → arbitrary file reads (CVSS 8.6)
• CVE-2025-54253: Struts2 devMode → unauthenticated RCE (CVSS 10.0)
#InfoSec #ThreatIntel
Struts Bootstrap plugin ver 6.0.0 is out, with support for Struts 7.0.0 and Java 17! Enjoy!
#struts #bootstrap #plugin #release #java
github.com/struts-commu...
Struts Bootstrap plugin ver 6.0.0 is out, with support for Struts 7.0.0 and Java 17! Enjoy!
#struts #bootstrap #plugin #release #java
github.com/struts-commu...
■【お知らせ】Apache Struts2の脆弱性(S2-067、CVE-2024-53677)において、クラウド型 WAF「Scutum」は2023年12月時点で対策済み | 脆弱性診断とクラウド型WAFのセキュアスカイ・テクノロジー(SST)
www.securesky-tech.com/2024/12/13/7...
■【お知らせ】Apache Struts2の脆弱性(S2-067、CVE-2024-53677)において、クラウド型 WAF「Scutum」は2023年12月時点で対策済み | 脆弱性診断とクラウド型WAFのセキュアスカイ・テクノロジー(SST)
www.securesky-tech.com/2024/12/13/7...
#lambda #cloud #apache #struts https://twitter.com/sapessi/status/1055202054879113216
#lambda #cloud #apache #struts https://twitter.com/sapessi/status/1055202054879113216
https://x.com/bulkneets/status/2000007927428739284
https://x.com/bulkneets/status/2000007927428739284
Posted by Daniel Owens via Fulldisclosure on Aug 29On 26 October 2025 we published "Struts2 and Related Framework Array/Collection DoS", which was followed up on 07 March
2026 by "JSON Deserialiser Unconstrain…
#hackernews #news
Posted by Daniel Owens via Fulldisclosure on Aug 29On 26 October 2025 we published "Struts2 and Related Framework Array/Collection DoS", which was followed up on 07 March
2026 by "JSON Deserialiser Unconstrain…
#hackernews #news
#ApacheStruts #Struts2 #DoS #CVE #JavaWeb #CyberSecurity #InfoSec #Vulnerability
#ApacheStruts #Struts2 #DoS #CVE #JavaWeb #CyberSecurity #InfoSec #Vulnerability