CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2012-0391

CVSS 9.8v3.1pub. 2012-01-08upd. 2026-04-22

The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apache Struts

    APP
    Apache
    < 2.2.3.1

CISA KEV — detailsi

Vendori
Apache
Producti
Struts 2
Added to KEVi
January 21, 2022
Remediation deadline (US Federal)i
July 21, 2022(overdue)
Required action (CISA)i

Apply updates per vendor instructions.

CISA descriptioni

The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 21 lipca 2022
CWE
References

Related vulnerabilities

CVE-2020-17530CRITICAL9.8⚠ KEVPL ✓same product

RCE w Apache Struts 2 poprzez wymuszoną ewaluację OGNL

CVE-2017-9791CRITICAL9.8⚠ KEVPL ✓same product

RCE w pluginie Struts 1 dla Apache Struts 2 (S2-048)

CVE-2017-5638CRITICAL9.8⚠ KEVPL ✓same product

RCE w Apache Struts 2 poprzez błędną obsługę nagłówków HTTP (Jakarta Multipart parser)

CVE-2013-2251CRITICAL9.8⚠ KEVPL ✓same product

Apache Struts 2: RCE przez prefiks action/redirect w parametrach

CVE-2024-53677CRITICAL9.5PL ✓same product

Apache Struts: RCE przez podatność path traversal przy upload plików