The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache Struts
APPApache2.3.12.3.1.12.3.1.22.3.122.3.142.3.14.12.3.14.22.3.14.32.3.152.3.15.12.3.15.22.3.15.32.3.162.3.16.12.3.16.2+ 18 more
CISA KEV — detailsi
- Vendori
- Apache ↗
- Producti
- Struts 1
- Added to KEVi
- February 10, 2022
- Remediation deadline (US Federal)i
- August 10, 2022(overdue)
Required action (CISA)i
Apply updates per vendor instructions.
CISA descriptioni
The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
⏰CISA DEADLINE: 10 sierpnia 2022
Tags
RCE
References
Related vulnerabilities
CVE-2020-17530CRITICAL9.8⚠ KEVPL ✓same product
RCE w Apache Struts 2 poprzez wymuszoną ewaluację OGNL
CVE-2017-5638CRITICAL9.8⚠ KEVPL ✓same product
RCE w Apache Struts 2 poprzez błędną obsługę nagłówków HTTP (Jakarta Multipart parser)
CVE-2013-2251CRITICAL9.8⚠ KEVPL ✓same product
Apache Struts 2: RCE przez prefiks action/redirect w parametrach
CVE-2012-0391CRITICAL9.8⚠ KEVPL ✓same product
Apache Struts: RCE przez OGNL injection w ExceptionDelegator
CVE-2024-53677CRITICAL9.5PL ✓same product
Apache Struts: RCE przez podatność path traversal przy upload plików