On CVE-2024-53677 (Struts vuln), it's following a very similar path to the Struts 2 vuln last year:
- Media are reporting it is being exploited in the wild. It isn't. People are spraying and praying - the exploit payloads don't work.
- People are posting a PoC for it. The PoC doesn't work. You'd have to make a vulnerable webapp, and then tailor the PoC to it.
Not to downplay it, just keep calm and patch. You may have noticed the internet didn't melt last time.
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.