Read: Apache Struts Patches ‘Critical Vulnerability’ CVE-2018-11776

Data-Privacy

On August 22, Apache Struts released a security patch fixing a critical remote code execution vulnerability. This vulnerability has been assigned CVE-2018-11776 (S2-057) and affects Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16.

The vulnerability was responsibly disclosed by Man Yue Mo from the Semmle Security Research team, check out a detailed description here. An exploit PoC has already been published.

Imperva WAF customers are protected out of the box against this vulnerability, no need for any special configuration on the customer end.