The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HApache Struts
APPApache2.1.2 – 2.3.34 (excl.)2.5.0 – 2.5.13 (excl.)Cisco Digital Media Manager
APPCiscoall versionsCisco Hosted Collaboration Solution
APPCisco10.5\(1\)11.0\(1\)11.5\(1\)11.6\(1\)Cisco Media Experience Engine
APPCisco3.53.5.2Cisco Network Performance Analysis
APPCiscoall versionsCisco Video Distribution Suite For Internet Streaming
APPCiscoall versionsNetapp Oncommand Balance
APPNetappall versions
CISA KEV — detailsi
- Vendori
- Apache ↗
- Producti
- Struts
- Added to KEVi
- November 3, 2021
- Remediation deadline (US Federal)i
- May 3, 2022(overdue)
Apply updates per vendor instructions.
Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.
Related vulnerabilities
RCE w Apache Struts 2 poprzez wymuszoną ewaluację OGNL
RCE w pluginie Struts 1 dla Apache Struts 2 (S2-048)
RCE w Apache Struts 2 poprzez błędną obsługę nagłówków HTTP (Jakarta Multipart parser)
Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX
Apache Struts 2: RCE przez prefiks action/redirect w parametrach