Untitled attachment
https://cyberplace.social/system/media_attachments/files/111/585/631/735/499/700/original/8765b1a7194905ab.png
A bit more on the CVE-2023-50164 hype train - Akamai are seeing same as myself and @shadowserver -
https://www.akamai.com/blog/security-research/apache-struts-cve-exploitation-attempts
Rather bafflingly I keep seeing people at security resellers trying to claim this is evidence of "nation state zero days".
To be super clear about this one, the request below is for a specific Tomcat webapp called 'upload' - the webapp has exactly one function, upload, which is set up to be exploitable by this CVE.
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.