Junglewise Threat Intelligence

CVE-2017-5638: Apache Struts vulnerable to remote arbitrary command execution due to improper input validation

CVE-2017-5638 · Severity: critical · CVSS 3 · Exploited in the wild · Published 2018-10-18

Technologies: Apache Struts 2, Apache Struts. Vendors: Apache.

Executive brief

The Jakarta Multipart parser in Apache Struts 2 fails to properly handle exceptions and error messages during file uploads. Remote attackers can exploit this by sending crafted Content-Type, Content-Disposition, or Content-Length HTTP headers to execute arbitrary commands.

Affected products

  • Apache Struts 2 2.3.x before 2.3.32, 2.5.x before 2.5.10.1

Timeline

  • 2017-03: exploited: Exploited in the wild with a Content-Type header containing a #cmd= string.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats