Junglewise Threat Intelligence

CVE-2020-17530: Remote code execution in Apache Struts

CVE-2020-17530 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2022-02-09

Technologies: Apache Struts 2, Apache Struts. Vendors: Apache, Maven.

Executive brief

Apache Struts 2 is vulnerable to Remote Code Execution due to forced OGNL evaluation of raw user input in tag attributes. An attacker can exploit this by submitting malicious OGNL expressions that the application then evaluates, leading to arbitrary code execution.

Affected products

  • Apache Struts 2 2.0.0 - 2.5.25

Timeline

  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed

Related threats