CVE-2018-11776
HIGH KEV RANSOMWARE NUCLEIApache Struts 2 Namespace Redirect OGNL Injection
Title source: metasploitDescription
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.
Exploits (28)
github
WRITEUP
3,480 stars
by qazbnm456 · poc
https://github.com/qazbnm456/awesome-cve-poc/tree/master/CVE-2018-11776.md
nomisec
WORKING POC
303 stars
by mazen160 · remote
https://github.com/mazen160/struts-pwn_CVE-2018-11776
nomisec
WORKING POC
123 stars
by hook-s3c · remote
https://github.com/hook-s3c/CVE-2018-11776-Python-PoC
github
WRITEUP
14 stars
by xbl3 · poc
https://github.com/xbl3/awesome-cve-poc_qazbnm456/tree/master/CVE-2018-11776.md
github
WRITEUP
3 stars
by HxDDD · poc
https://github.com/HxDDD/CVE-PoC/tree/main/Apache/(RCE) CVE-2018-11776.md
nomisec
WORKING POC
by OzNetNerd · poc
https://github.com/OzNetNerd/apche-struts-vuln-demo-cve-2018-11776
metasploit
WORKING POC
EXCELLENT
by Man Yue Mo, hook-s3c, asoto-r7, wvu · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/struts2_namespace_ognl.rb
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/45367
Nuclei Templates (1)
Apache Struts2 S2-057 - Remote Code Execution
HIGHby pikpikcu
Shodan:
http.html:"apache struts" || http.title:"struts2 showcase" || http.html:"struts problem report"
FOFA:
body="struts problem report" || title="struts2 showcase" || body="apache struts"
References (20)
Scores
CVSS v3
8.1
EPSS
0.9443
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Intel
CISA KEV
2021-11-03
VulnCheck KEV
2018-12-18
InTheWild.io
2021-07-23
ENISA EUVD
EUVD-2018-0582
Ransomware Use
Confirmed
Classification
Status
published
Affected Products (11)
apache/struts
< 2.3.35
netapp/active_iq_unified_manager
netapp/active_iq_unified_manager
netapp/oncommand_insight
netapp/oncommand_workflow_automation
netapp/snapcenter
oracle/communications_policy_management
< 12.5.0
oracle/enterprise_manager_base_platform
oracle/enterprise_manager_base_platform
oracle/mysql_enterprise_monitor
< 3.4.9.4237
org.apache.struts/struts2-core
< 2.3.35Maven
Timeline
Published
Aug 22, 2018
KEV Added
Nov 03, 2021
Tracked Since
Feb 18, 2026