Junglewise Threat Intelligence

CVE-2017-9791: Code execution in Apache Struts 1 plugin

CVE-2017-9791 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2022-05-13

Technologies: Apache Struts 2. Vendors: Apache, Maven.

Executive brief

The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x allows remote code execution via improper input validation. An attacker can exploit this by passing a malicious field value in a raw message to the ActionMessage function.

Affected products

  • Apache Struts 2 2.1.x, 2.3.x

Timeline

  • 2022-02-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-02-10: disclosed

Related threats