The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache Struts
APPApache< 2.2.3.1
CISA KEV — detailsi
- Vendori
- Apache ↗
- Producti
- Struts 2
- Added to KEVi
- January 21, 2022
- Remediation deadline (US Federal)i
- July 21, 2022(overdue)
Apply updates per vendor instructions.
The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.
Related vulnerabilities
RCE w Apache Struts 2 poprzez wymuszoną ewaluację OGNL
RCE w pluginie Struts 1 dla Apache Struts 2 (S2-048)
RCE w Apache Struts 2 poprzez błędną obsługę nagłówków HTTP (Jakarta Multipart parser)
Apache Struts 2: RCE przez prefiks action/redirect w parametrach
Apache Struts: RCE przez podatność path traversal przy upload plików