Junglewise Threat Intelligence

CVE-2017-9805: REST Plugin in Apache Struts uses an XStreamHandler with an instance of XStream for deserialization without any type filtering

CVE-2017-9805 · Severity: critical · CVSS 3 · Exploited in the wild · Published 2018-10-16

Technologies: Apache Struts. Vendors: Apache.

Executive brief

The REST Plugin in Apache Struts uses an XStreamHandler for deserialization without proper type filtering. This vulnerability allows remote attackers to execute arbitrary code by sending specially crafted XML payloads.

Affected products

  • Apache Struts REST Plugin 2.1.1 through 2.3.33, 2.5.x before 2.5.13

Timeline

  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed

Related threats