Executive brief
Apache Struts is vulnerable to Remote Code Execution (RCE) when the alwaysSelectFullNamespace option is enabled. The flaw occurs when results or URL tags are used without a defined namespace while the upper package configuration uses no namespace or a wildcard namespace, allowing for malicious OGNL expression evaluation.
Affected products
- Apache Struts 2.3 to 2.3.34, 2.5 to 2.5.16
Timeline
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: disclosed