Remote command execution In org.apache.struts:struts2-core
Description
Expression Language Injection in Apache Struts The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
maven | 2.5.30 | ||
maven | 2.5.30 | ||
maven | 2.5.30 | ||
maven | - | ||
maven | 2.5.30 | ||
maven | - |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5. 6. 7. 8.