CRITICAL9.8
GHSA-jc35-q369-45pv
Remote code execution in Apache Struts
Quick fix
GHSA-jc35-q369-45pv — org.apache.struts:struts2-core: upgrade to the fixed version with the command below.
# pom.xml: bump <version>2.5.26</version> for org.apache.struts:struts2-coreDetails
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.apache.struts:struts2-core
Introduced in:
2.0.0Fixed in: 2.5.26Fix
# pom.xml: bump <version>2.5.26</version> for org.apache.struts:struts2-coreReferences
- https://nvd.nist.gov/vuln/detail/CVE-2020-17530[ADVISORY]
- https://cwiki.apache.org/confluence/display/WW/S2-061[WEB]
- https://github.com/apache/struts[PACKAGE]
- https://security.netapp.com/advisory/ntap-20210115-0005[WEB]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-17530[WEB]
- https://www.oracle.com//security-alerts/cpujul2021.html[WEB]
- https://www.oracle.com/security-alerts/cpuApr2021.html[WEB]
- https://www.oracle.com/security-alerts/cpuapr2022.html[WEB]
- https://www.oracle.com/security-alerts/cpujan2021.html[WEB]
- https://www.oracle.com/security-alerts/cpujan2022.html[WEB]
- https://www.oracle.com/security-alerts/cpuoct2021.html[WEB]
- http://jvn.jp/en/jp/JVN43969166/index.html[WEB]
- http://packetstormsecurity.com/files/160721/Apache-Struts-2-Forced-Multi-OGNL-Evaluation.html[WEB]
- http://www.openwall.com/lists/oss-security/2022/04/12/6[WEB]