Executive brief
Apache Struts 2 is vulnerable to Remote Code Execution due to forced OGNL evaluation of raw user input in tag attributes. An attacker can exploit this by submitting malicious OGNL expressions that the application then evaluates, leading to arbitrary code execution.
Affected products
- Apache Struts 2 2.0.0 - 2.5.25
Timeline
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: disclosed