Junglewise Threat Intelligence

CVE-2013-2251: Code injection in Apache Struts

CVE-2013-2251 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2022-05-13

Technologies: Apache Struts 2, Apache Struts. Vendors: Apache, Maven.

Executive brief

Apache Struts 2 allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions via crafted parameters using action:, redirect:, or redirectAction: prefixes. This improper input validation vulnerability can lead to remote code execution.

Affected products

  • Apache Struts 2 2.0.0 through 2.3.15

Timeline

  • 2013-07-16: advisory: Original Apache Struts S2-016 advisory date
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-25: disclosed: NVD publication date

Related threats