Threat actors are targeting a critical flaw in the Apache OFBiz platform that was disclosed in late December.
The Apache Software Foundation has released updates to address a critical file upload vulnerability (CVE-2023-50164) in Struts.
Apache disclosed this flaw and released patches for it on Oct. 25, and proof-of-concept exploit code is also available for the bug.
The Apache Software Foundation has fixed two important security flaws in version 2.4.56 of its HTTP Server.
Details about the severity and scope of the vulnerability are still emerging, including the detection of any examples of real-world applications using vulnerable configurations of the impacted library.