Dec. 22, 2023, 3:22 p.m. | Mary

AboutDFIR – The Definitive Compendium Project aboutdfir.com

Four in five Apache Struts 2 downloads are for versions featuring critical flaw  Security vendor Sonatype believes developers are failing to address the critical remote code execution (RCE) vulnerability in the Apache Struts 2 framework, based on recent downloads of the code. The vulnerability, tracked as CVE-2023-50164, is rated 9.8 out of 10 in terms of CVSS severity. […]


The post InfoSec News Nuggets 12/22/2023 appeared first on AboutDFIR - The Definitive Compendium Project.

aboutdfir address apache apache struts apache struts 2 code code execution critical critical flaw cve cve-2023-50164 developers downloads flaw framework ftc infosec infosec news infosec news nuggets news nuggets nuggets rce remote code remote code execution rite aid security security vendor sonatype struts struts 2 terms vendor vulnerability

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC