{"id":121007,"date":"2024-12-17T21:46:00","date_gmt":"2024-12-17T19:46:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-apache-struts-pozvolyayushhaya-vypolnit-kod-na-servere"},"modified":"2024-12-17T21:46:00","modified_gmt":"2024-12-17T19:46:00","slug":"uyazvimost-v-apache-struts-pozvolyayushhaya-vypolnit-kod-na-servere","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-apache-struts-pozvolyayushhaya-vypolnit-kod-na-servere","title":{"rendered":"Vuln\u00e9rabilit\u00e9 dans Apache Struts permettant l'ex\u00e9cution de code sur le serveur","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Dans le framework web Apache Struts, utilis\u00e9 pour cr\u00e9er des applications web en Java selon le paradigme MVC (Model-View-Controller), une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte (CVE-2024-53677). Cette vuln\u00e9rabilit\u00e9 permet \u00e0 un attaquant externe d'\u00e9crire un fichier \u00e0 un emplacement arbitraire sur le syst\u00e8me de fichiers du serveur en envoyant une requ\u00eate HTTP sp\u00e9cifiquement format\u00e9e. Le probl\u00e8me concerne les versions de 2.0.0 \u00e0 2.3.37, de 2.5.0 \u00e0 2.5.33 et de 6.0.0 \u00e0 6.3.0.2, et se manifeste dans les applications utilisant le composant FileUploadInterceptor pour le t\u00e9l\u00e9chargement de fichiers sur le serveur.      <\/p>\n<p>La vuln\u00e9rabilit\u00e9 est caus\u00e9e par l'absence de v\u00e9rification ad\u00e9quate des param\u00e8tres transmis lors du t\u00e9l\u00e9chargement de fichiers. En ayant acc\u00e8s aux fonctions de t\u00e9l\u00e9chargement de fichiers dans l'interface web bas\u00e9e sur Apache Struts, un attaquant peut sp\u00e9cifier une valeur telle que \u00ab ..\\\/..\\\/..\\\/..\\\/..\\\/webapps\\\/ROOT \u00bb et r\u00e9ussit \u00e0 enregistrer un fichier en dehors du r\u00e9pertoire de stockage des donn\u00e9es t\u00e9l\u00e9charg\u00e9es (prototype d'exploit). En obtenant la possibilit\u00e9 d'\u00e9crire des fichiers dans des parties arbitraires du syst\u00e8me de fichiers, il est possible d'organiser l'ex\u00e9cution de ses propres commandes sur <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/fr\/server\/dts-newyork\/\"   title=\"le serveur\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"2792\">le serveur<\/a>, en \u00e9crasant des scripts ou des fichiers de configuration, selon les droits de l'utilisateur sous lequel l'application web s'ex\u00e9cute. Si l'application web s'ex\u00e9cute dans un conteneur Apache Tomcat avec des droits root, l'attaquant peut obtenir un acc\u00e8s privil\u00e9gi\u00e9 au syst\u00e8me.     <\/p>\n<p>Les vuln\u00e9rabilit\u00e9s dans Apache Struts sont significatives car ce framework est populaire dans les syst\u00e8mes d'entreprise accessibles via le web. Selon les statistiques de RedMonk, le framework Apache Struts a \u00e9t\u00e9 utilis\u00e9 dans des applications web par 65 % des entreprises du classement Fortune 100. En 2017, une attaque contre le syst\u00e8me d'information de l'entreprise Equifax, utilisant une version vuln\u00e9rable d'Apache Struts, a conduit \u00e0 la fuite de donn\u00e9es personnelles de 143 millions d'habitants des \u00c9tats-Unis.<br \/>\n<br \/>Source : <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=62424\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 web-\u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0435 Apache Struts, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f web-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 \u043d\u0430 \u044f\u0437\u044b\u043a\u0435 Java \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u043f\u0430\u0440\u0430\u0434\u0438\u0433\u043c\u044b \u041cV\u0421 (Model-View-Controller), \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2024-53677). \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0434\u0430\u0451\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0432\u043d\u0435\u0448\u043d\u0435\u043c\u0443 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0443 \u0437\u0430\u043f\u0438\u0441\u0430\u0442\u044c \u0444\u0430\u0439\u043b \u0432 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u043e\u0435 \u043c\u0435\u0441\u0442\u043e \u0444\u0430\u0439\u043b\u043e\u0432\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e HTTP-\u0437\u0430\u043f\u0440\u043e\u0441\u0430. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u0435\u0442 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u0441 2.0.0 \u043f\u043e 2.3.37, c 2.5.0 \u043f\u043e 2.5.33 \u0438 \u0441 6.0.0 \u043f\u043e 6.3.0.2, \u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-121007","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 web-\u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0435 Apache Struts, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f web-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 \u043d\u0430 \u044f\u0437\u044b\u043a\u0435 Java \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u043f\u0430\u0440\u0430\u0434\u0438\u0433\u043c\u044b \u041cV\u0421 (Model-View-Controller), \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2024-53677).\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-apache-struts-pozvolyayushhaya-vypolnit-kod-na-servere\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Apache Struts, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 web-\u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0435 Apache Struts, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f web-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 \u043d\u0430 \u044f\u0437\u044b\u043a\u0435 Java \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u043f\u0430\u0440\u0430\u0434\u0438\u0433\u043c\u044b \u041cV\u0421 (Model-View-Controller), \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2024-53677).\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-apache-struts-pozvolyayushhaya-vypolnit-kod-na-servere\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-12-17T19:46:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-12-17T19:46:00+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vuln\u00e9rabilit\u00e9 dans Apache Struts permettant d'ex\u00e9cuter du code sur le serveur | ProHoster","description":"Dans le framework web Apache Struts, utilis\u00e9 pour cr\u00e9er des applications web en Java selon le paradigme MVC (Model-View-Controller), une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte (CVE-2024-53677).","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-apache-struts-pozvolyayushhaya-vypolnit-kod-na-servere","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Apache Struts, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 | ProHoster","og:description":"\u0412 web-\u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0435 Apache Struts, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f web-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 \u043d\u0430 \u044f\u0437\u044b\u043a\u0435 Java \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u043f\u0430\u0440\u0430\u0434\u0438\u0433\u043c\u044b \u041cV\u0421 (Model-View-Controller), \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2024-53677).","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-apache-struts-pozvolyayushhaya-vypolnit-kod-na-servere","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2024-12-17T19:46:00+00:00","article:modified_time":"2024-12-17T19:46:00+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"121007","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-09 22:04:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 08:57:19","updated":"2026-02-09 22:04:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/121007","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=121007"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/121007\/revisions"}],"predecessor-version":[{"id":160072,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/121007\/revisions\/160072"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=121007"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=121007"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=121007"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}