Apache Struts 2 Namespace Redirect OGNL Injection
Title source: metasploitDescription
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.
Exploits (28)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/45367
github
WRITEUP
3,480 stars
by qazbnm456 · poc
https://github.com/qazbnm456/awesome-cve-poc/tree/master/CVE-2018-11776.md
nomisec
WORKING POC
303 stars
by mazen160 · remote
https://github.com/mazen160/struts-pwn_CVE-2018-11776
nomisec
WORKING POC
123 stars
by hook-s3c · remote
https://github.com/hook-s3c/CVE-2018-11776-Python-PoC
github
WRITEUP
14 stars
by xbl3 · poc
https://github.com/xbl3/awesome-cve-poc_qazbnm456/tree/master/CVE-2018-11776.md
github
WRITEUP
3 stars
by HxDDD · poc
https://github.com/HxDDD/CVE-PoC/tree/main/Apache/(RCE) CVE-2018-11776.md
nomisec
WORKING POC
by OzNetNerd · poc
https://github.com/OzNetNerd/apche-struts-vuln-demo-cve-2018-11776
metasploit
WORKING POC
EXCELLENT
by Man Yue Mo, hook-s3c, asoto-r7, wvu · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/struts2_namespace_ognl.rb
Nuclei Templates (1)
Apache Struts2 S2-057 - Remote Code Execution
HIGHby pikpikcu
Shodan:
http.html:"apache struts" || http.title:"struts2 showcase" || http.html:"struts problem report"
FOFA:
body="struts problem report" || title="struts2 showcase" || body="apache struts"
References (20)
Scores
CVSS v3
8.1
EPSS
0.9443
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Lab Environment
COMMUNITY
Community Lab
+19 more repos
Details
CISA KEV
2021-11-03
VulnCheck KEV
2018-12-18
InTheWild.io
2021-07-23
ENISA EUVD
EUVD-2018-0582
Ransomware Use
Confirmed
Status
published
Products (11)
apache/struts
2.0.4 - 2.3.35
netapp/active_iq_unified_manager
7.3
netapp/active_iq_unified_manager
9.5
netapp/oncommand_insight
netapp/oncommand_workflow_automation
netapp/snapcenter
oracle/communications_policy_management
< 12.5.0
oracle/enterprise_manager_base_platform
13.3.0.0
oracle/enterprise_manager_base_platform
13.4.0.0
oracle/mysql_enterprise_monitor
< 3.4.9.4237
... and 1 more
Published
Aug 22, 2018
KEV Added
Nov 03, 2021
Tracked Since
Feb 18, 2026