Executive brief
The Jakarta Multipart parser in Apache Struts 2 fails to properly handle exceptions and error messages during file uploads. Remote attackers can exploit this by sending crafted Content-Type, Content-Disposition, or Content-Length HTTP headers to execute arbitrary commands.
Affected products
- Apache Struts 2 2.3.x before 2.3.32, 2.5.x before 2.5.10.1
Timeline
- 2017-03: exploited: Exploited in the wild with a Content-Type header containing a #cmd= string.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.