Junglewise Threat Intelligence

CVE-2018-11776: Apache Struts vulnerable to remote command execution (RCE) due to improper input validation

CVE-2018-11776 · Severity: critical · CVSS 3 · Exploited in the wild · Published 2018-10-18

Technologies: Apache Struts. Vendors: Apache.

Executive brief

Apache Struts is vulnerable to Remote Code Execution (RCE) when the alwaysSelectFullNamespace option is enabled. The flaw occurs when results or URL tags are used without a defined namespace while the upper package configuration uses no namespace or a wildcard namespace, allowing for malicious OGNL expression evaluation.

Affected products

  • Apache Struts 2.3 to 2.3.34, 2.5 to 2.5.16

Timeline

  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed

Related threats