logo

Database

Lack of data validation In org.apache.struts:struts2-core

Description

Apache Struts vulnerable to remote command execution (RCE) due to improper input validation Apache Struts contains a Remote Code Execution when using results with no namespace and it's upper actions have no or wildcard namespace. The same flaw exists when using a url tag with no value, action set, and it's upper actions have no or wildcard namespace.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions

References

1. https://github.com/apache/struts/commit/6e87474f9ad0549f07dd2c37d50a9ccd0977c6e2. https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html3. https://www.oracle.com/security-alerts/cpujul2020.html4. https://www.exploit-db.com/exploits/453675. https://www.exploit-db.com/exploits/452626. https://www.exploit-db.com/exploits/452607. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-117768. https://web.archive.org/web/20201208145803/https://securitytracker.com/id/10415479. https://web.archive.org/web/20200807025819/http://www.securitytracker.com/id/104188810. https://web.archive.org/web/20180822160726/http://www.securityfocus.com/bid/10512511. https://security.netapp.com/advisory/ntap-20181018-000212. https://security.netapp.com/advisory/ntap-20180822-000113. https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-001214. https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c@%3Cannounce.apache.org%3E15. https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E16. https://lgtm.com/blog/apache_struts_CVE-2018-1177617. https://github.com/hook-s3c/CVE-2018-11776-Python-PoC18. https://cwiki.apache.org/confluence/display/WW/S2-05719. http://packetstormsecurity.com/files/172830/Apache-Struts-Remote-Code-Execution.html20. http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-005.txt21. http://www.oracle.com/technetwork/security-advisory/alert-cve-2018-11776-5072787.html22. http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html23. http://www.securityfocus.com/bid/10512524. http://www.securitytracker.com/id/104154725. http://www.securitytracker.com/id/104188826. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-11776.yaml27. https://github.com/xfox64x/CVE-2018-1177628. https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/struts2_namespace_ognl.rb