Apache Struts
cpe:2.3:a:apache:struts:*:*:*:*:*:*:*
- >= 2.0.0, <= 2.3.15
This vulnerability is being actively exploited in the wild.
A remote code execution vulnerability has been identified in Apache Struts versions 2.0.0 through 2.3.15. This vulnerability allows attackers to execute arbitrary OGNL expressions by sending crafted requests with specific prefixes, such as action:, redirect:, or redirectAction:. The issue arises from inadequate sanitization of user input, enabling the execution of malicious code on the server.
Exploitation of this vulnerability allows for arbitrary code execution on the affected server.
To reproduce this vulnerability, send a request to the server running an affected version of Apache Struts. Include a parameter with a crafted OGNL expression, using one of the vulnerable prefixes (action:, redirect:, or redirectAction:). The server's response should indicate that the OGNL expression has been executed, demonstrating successful exploitation.
Users are advised to upgrade to Apache Struts versions later than 2.3.15. For guidance on updating, consult the Apache Struts documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.