UDS-HTTP: Apache Struts file upload vulnerability (CVE-2024-53677)
A Trellix Intrusion Prevention System (IPS) Emergency User Defined Signature (UDS) has been created to detect this threat.
Environment
Summary
A UDS is intended to cover the known aspects of a threat and might not cover all variants. Sometimes, UDS releases might generate incorrect identification.
To download a UDS, perform the steps below:
-
Click the link to the Knowledge Base article for the UDS that you need to download.
UDSs Release Date Threat Article December 17, 2024 UDS-HTTP: Apache Struts file upload vulnerability (CVE-2024-53677) Release Notes December 2, 2024 UDS-HTTP: WordPress Plugin PegaPoll privilege escalation vulnerability (CVE-2024-50490) Release Notes November 22, 2024 UDS for multiple vulnerabilities Release Notes November 5, 2024 UDS for multiple vulnerabilities Release Notes -
Download the .zip file attached to the article, which contains the UDS.
Note: The .zip file is named using the format UDS <date of release>.zip.
For example, UDS-11042020.zip was released on November 4, 2020. -
Extract the downloaded .zip file.
The .zip file extracts into Emergency_UDS_xxx.zip.
To import the UDS to the Manager, perform the steps below:
- Log on to the Manager.
-
Click Policy > Intrusion Prevention > Policy Types.
- For Manager 9.x, click IPS Policies.
- For Manager 10.x and later, including 11.x, click IPS.
- Click the Custom Attacks link at the bottom of the left pane.
- Click Other Actions and Import.
- Click Browse and select the Emergency_UDS_xxx.zip file.
-
Deselect the following:
- Import Snort Rules
- Import Snort Macros
- Import Snort Classifications
- Click Import.
- Verify that the number of UDSs that are successfully imported is not zero (1 or greater).
Push the UDS from the Manager to the Sensors:
The imported UDS is not pushed to the Sensor until you perform an update. You can roll out the update using either of the following methods:
- Open the Manager.
- Navigate to Devices.
- From the left navigation pane, select the Devices tab.
- From the drop-down list, select the Sensor that you want to push the update to.
- Click Deploy Pending Changes. The option must already be selected.
- To start updating the Sensor, click Update/Deploy.
- Open the Manager.
- Navigate to Devices.
- From the left navigation pane, select the Global tab.
- Click Deploy Pending Changes. Each Sensor requiring an update must be selected.
- To start updating the Sensors, click Update/Deploy.
Related information
References to product versions that have reached End of Life have been removed from this article. We strongly recommend that you upgrade to a supported version.
For details on supported and End-of-Life (EOL) products, see Trellix Product End-of-Life Information.