Executive brief
Apache Struts 2 allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions via crafted parameters using action:, redirect:, or redirectAction: prefixes. This improper input validation vulnerability can lead to remote code execution.
Affected products
- Apache Struts 2 2.0.0 through 2.3.15
Timeline
- 2013-07-16: advisory: Original Apache Struts S2-016 advisory date
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-25: disclosed: NVD publication date