Description
The file upload mechanism in Apache Struts contains a vulnerability. An attacker can exploit this by manipulating file upload parameters to perform path traversal, potentially allowing the upload of a malicious file. Under certain conditions, this can lead to Remote Code Execution (RCE)
Remediation
Upgrade at least to Struts 6.4.0 (or the latest version) and migrate to the new file upload mechanism.