CVE-2019-0233
published 2020-09-14CVE-2019-0233: An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.
PriorityP355high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
68.76%
99.3th percentile
An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | struts | 2.0.0 – 2.5.20 | — |
| oracle | communications_policy_management | — | — |
| oracle | financial_services_data_integration_hub | — | — |
| oracle | financial_services_data_integration_hub | — | — |
| oracle | financial_services_market_risk_measurement_and_management | — | — |
| oracle | mysql_enterprise_monitor | <= 8.0.23 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2019-0233 is triggered during a file upload to an Action that exposes the file with a getter; an attacker manipulates the request so the uploaded file is set to read-only, causing subsequent file operations to fail. ↗
- →The attack may also target the Servlet container's temp directory, setting it to read-only to cause all subsequent upload actions to fail — monitor for unexpected permission changes on the container temp directory. ↗
- →Affected versions are Apache Struts 2.0.0 through 2.5.20; flag any deployment running these versions handling file uploads as at-risk for DoS via this CVE. ↗
- →Refer to Apache Struts security bulletin S2-060 for the authoritative technical description of the file-upload permission-override attack vector. ↗
- ·CVE-2019-0233 is a DoS-only vulnerability (access permission override during file upload); it does not enable remote code execution. Do not conflate with the co-disclosed CVE-2019-0230 (OGNL RCE). ↗
- ·Red Hat JBoss Enterprise Application Platform 6, JBoss Fuse Service Works 6, JBoss Operations Network 3, and Red Hat OpenStack Platform 10 (opendaylight) are confirmed Not Affected; only Red Hat Enterprise Linux 5 (struts package) is listed as out-of-support-scope. ↗
- ·Exploitation requires the Struts Action to expose the uploaded file via a getter; applications not structured this way may not be exploitable. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Preservation of Permissions in Apache Struts
osv·2022-05-24
CVE-2019-0233 [HIGH] Improper Preservation of Permissions in Apache Struts
Improper Preservation of Permissions in Apache Struts
An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.
GHSA
Improper Preservation of Permissions in Apache Struts
ghsa·2022-05-24
CVE-2019-0233 [HIGH] CWE-281 Improper Preservation of Permissions in Apache Struts
Improper Preservation of Permissions in Apache Struts
An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.
Red Hat
struts2: access permission override when performing a file upload leads to DoS
vendor_redhat·2020-08-11·CVSS 7.5
CVE-2019-0233 [HIGH] CWE-284 struts2: access permission override when performing a file upload leads to DoS
struts2: access permission override when performing a file upload leads to DoS
An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.
Package: struts (Red Hat Enterprise Linux 5) - Out of support scope
Package: struts (Red Hat JBoss Enterprise Application Platform 6) - Not affected
Package: struts (Red Hat JBoss Fuse Service Works 6) - Not affected
Package: struts (Red Hat JBoss Operations Network 3) - Not affected
Package: opendaylight (Red Hat OpenStack Platform 10 (Newton)) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-0233 struts2: access permission override when performing a file upload leads to DoS
bugzilla·2020-08-18·CVSS 7.5
CVE-2019-0233 [HIGH] CVE-2019-0233 struts2: access permission override when performing a file upload leads to DoS
CVE-2019-0233 struts2: access permission override when performing a file upload leads to DoS
When a file upload is performed to an Action that exposes the file with a getter, an attacker may manipulate the request such that the working copy of the uploaded file is set to read-only. As a result, subsequent actions on the file will fail with an error. It might also be possible to set the Servlet container's temp directory to read only, such that subsequent upload actions will fail.
Reference:
https://cwiki.apache.org/confluence/display/WW/S2-060
Discussion:
*** Bug 1872550 has been marked as a duplicate of this bug. ***
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-0233
Checkpoint
24th August – Threat Intelligence Bulletin
blogs_checkpoint·2020-08-24
CVE-2020-1530 24th August – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 24th August – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 24th August 2020, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
The University of Utah has paid $457K to prevent attackers from publishing student and employee information stolen during a ransomware attack which ended on July 19 th . The ransom has been paid by the university’s cyber insurer.
Taiwan has blamed four Chinese APT groups: Blacktech, Taidoor, MustangPanda and APT40 f
Tenable
CVE-2019-0230: Apache Struts Potential Remote Code Execution Vulnerability
blogs_tenable·2020-08-14·CVSS 9.8
[CRITICAL] CVE-2019-0230: Apache Struts Potential Remote Code Execution Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
https://cwiki.apache.org/confluence/display/ww/s2-060https://launchpad.support.sap.com/#/notes/2982840https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://cwiki.apache.org/confluence/display/ww/s2-060https://launchpad.support.sap.com/#/notes/2982840https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2020-09-14
Published