Report Incident
× Home Cybertech Africa 2023 2 DPO Rw-CSIRT Website About Rw-CSIRT Alerts Advisories About NCSA Documentation News & Events Topics Contact us Opportunities Privacy Policy

Alert: Apache Security Updates – December 2023

Apache Software Foundation issued a critical security update addressing Struts 2 file upload vulnerability (CVE-2023-50164), warning of potential remote code execution.
 
Affected Systems:
 
 
Security Risks
 
The successful exploitation of this vulnerability enables an attacker to manipulate file upload parameters, potentially allowing path traversal. This manipulation could lead to the upload of a malicious file, escalating the risk of remote code execution.
 
Recommended Actions
 
The National Cyber Security Authority (NCSA) strongly recommends to system administrators to:
 
  • Follow Apache Struts Security Advisory S2-066 to lower the risk of potential exploits, protect systems, and ensure their security.
  • Apply the required and latest security updates as soon as possible.
 
The recommended software versions for upgrade are:
 
  • Apache Struts versions: 2.5.33 , 6.3.0.2 or greater.
  • Before any update task, please ensure you have a recent backup that can easily be restored.
 
For further information and support, please contact NCSA by email at rwcsirt@ncsa.gov.rw or call us on 9009.
 
References

13 December 2023

© 2025 National Cyber Security Authority