Showing 18 vulnerabilities on this page for Struts

Signals CISA KEV Ransomware Nuclei
apache vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.

CWE-112CWE-611Jan 11, 20261 related artifact
CVSS8.1v3.1EPSS37.1%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks

File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. This issue affects Apache Struts: from 2.0.0 before 6.4.0. Users are recommended to upgrade to version 6.4.0 at least and migrate to the new file upload mechanism https://struts.apache.org/core-developers/file-upload . If you are not using an old file up

CVSS9.5v4.0EPSS78.2%PoCs16SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apache Struts: File upload component had a directory traversal vulnerability

An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue.

CWE-552Dec 7, 2023
CVSS9.8v3.1EPSS80.8%PoCs13SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.

The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.

CWE-917Apr 12, 20221 related artifact
CVSS9.8v3.1EPSS85.4%PoCs7SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Remote code execution in Apache Struts

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.

CWE-917CWE-94Dec 11, 20201 related artifact
CVSS9.8v3.1EPSS95.6%PoCs14SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Struts ParameterInterceptor vulnerability allows remote command execution

Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.

CWE-732CWE-94Nov 1, 2019
CVSS9.8v3.1EPSS88.4%PoCs2SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apache Struts vulnerable to remote command execution (RCE) due to improper input validation

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.

CWE-20Aug 22, 20181 related artifact
CVSS8.1v3.1EPSS>99.9%PoCs19SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Apache Struts 2.0.1 uses an unintentional expression in a Freemarker tag instead of string literal

In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.

CWE-20Sep 20, 20171 related artifact
CVSS9.8v3.0EPSS87.1%PoCs3SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

REST Plugin in Apache Struts uses an XStreamHandler with an instance of XStream for deserialization without any type filtering

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.

CWE-502Sep 15, 20171 related artifact
CVSS8.1v3.1EPSS99.4%PoCs20SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Code execution in Apache Struts 1 plugin

The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.

CWE-20Jul 10, 20171 related artifact
CVSS9.8v3.1EPSS98.9%PoCs6SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Apache Struts vulnerable to remote arbitrary command execution due to improper input validation

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.

CWE-20CWE-755Mar 11, 20171 related artifact
CVSS9.8v3.1EPSS>99.9%PoCs82SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Apache Struts RCE Vulnerability

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.

CWE-77Apr 26, 20161 related artifact
CVSS8.1v3.0EPSS92.9%PoCs2SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

ClassLoader manipulation in Apache Struts

ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.

CWE-264Apr 29, 2014
CVSS7.5v2.0EPSS97.9%PoCs3SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ClassLoader manipulation in Apache Struts

CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.

CWE-264Apr 29, 2014
CVSS7.5v2.0EPSS77.8%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ClassLoader manipulation in Apache Struts

The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.

Mar 10, 2014
CVSS5.0v2.0EPSS99.5%PoCs4SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Code injection in Apache Struts

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

CWE-20CWE-74Jul 18, 20131 related artifact
CVSS9.8v3.1EPSS>99.9%PoCs4SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Arbitrary code execution in Apache Struts 2

Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly handled during wildcard matching, a different vulnerability than CVE-2013-2135.

CWE-94Jul 16, 2013
CVSS9.3v2.0EPSS70.2%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improper Input Validation in Apache Struts

ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.

CWE-20CWE-749Mar 30, 2006
CVSS7.5v3.1EPSS54.6%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX