CRITICAL

CVE-2020-17530

Apache Struts 2020-12-11 CVSS v3.1
CVSS
9.8
KEV

Description

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.

Summary dbcve.org

OGNL injection vulnerability in Apache Struts 2 where raw user input in tag attributes is evaluated as OGNL expressions, allowing attackers to execute arbitrary code on the server. This is a critical remote code execution flaw affecting Struts versions 2.0.0 through 2.5.25.

Mitigation

Upgrade Apache Struts to version 2.5.26 or later to patch the vulnerability. Additionally, avoid using raw user-supplied input directly in Struts tag attributes and implement proper input validation.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-917

EPSS Score

95.93%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE