CVE-2018-11776

HIGH KEV RANSOMWARE NUCLEI LAB

Apache Struts 2 Namespace Redirect OGNL Injection

Title source: metasploit

Description

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.

Exploits (28)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/45367
exploitdb WORKING POC
by Mazin Ahmed · pythonremotelinux
https://www.exploit-db.com/exploits/45260
exploitdb WORKING POC
by hook-s3c · pythonremotemultiple
https://www.exploit-db.com/exploits/45262
github WRITEUP 3,480 stars
by qazbnm456 · poc
https://github.com/qazbnm456/awesome-cve-poc/tree/master/CVE-2018-11776.md
nomisec WORKING POC 303 stars
by mazen160 · remote
https://github.com/mazen160/struts-pwn_CVE-2018-11776
nomisec WORKING POC 123 stars
by hook-s3c · remote
https://github.com/hook-s3c/CVE-2018-11776-Python-PoC
nomisec WORKING POC 55 stars
by 649 · remote
https://github.com/649/Apache-Struts-Shodan-Exploit
nomisec WORKING POC 21 stars
by Ekultek · remote
https://github.com/Ekultek/Strutter
nomisec WORKING POC 16 stars
by brianwrf · remote
https://github.com/brianwrf/S2-057-CVE-2018-11776
nomisec WORKING POC 15 stars
by arlyone · poc
https://github.com/arlyone/Apache-Struts-0Day-Exploit
nomisec WRITEUP 15 stars
by xfox64x · remote
https://github.com/xfox64x/CVE-2018-11776
github WRITEUP 14 stars
by xbl3 · poc
https://github.com/xbl3/awesome-cve-poc_qazbnm456/tree/master/CVE-2018-11776.md
nomisec WORKING POC 12 stars
by bhdresh · remote
https://github.com/bhdresh/CVE-2018-11776
nomisec SCANNER 10 stars
by jiguangsdf · remote
https://github.com/jiguangsdf/CVE-2018-11776
nomisec WORKING POC 4 stars
by knqyf263 · remote
https://github.com/knqyf263/CVE-2018-11776
github WRITEUP 3 stars
by HxDDD · poc
https://github.com/HxDDD/CVE-PoC/tree/main/Apache/(RCE) CVE-2018-11776.md
nomisec WORKING POC 3 stars
by tuxotron · remote
https://github.com/tuxotron/cve-2018-11776-docker
nomisec STUB 1 stars
by cved-sources · poc
https://github.com/cved-sources/cve-2018-11776
gitlab WORKING POC
by drent · poc
https://gitlab.com/drent/S2-057-CVE-2018-11776
nomisec WORKING POC
by m4sk0ff · remote
https://github.com/m4sk0ff/CVE-2018-11776
nomisec WORKING POC
by sonpt-afk · remote
https://github.com/sonpt-afk/CVE-2018-11776-FIS
nomisec WORKING POC
by OzNetNerd · poc
https://github.com/OzNetNerd/apche-struts-vuln-demo-cve-2018-11776
nomisec WORKING POC
by freshdemo · remote
https://github.com/freshdemo/ApacheStruts-CVE-2018-11776
nomisec WRITEUP
by cucadili · poc
https://github.com/cucadili/CVE-2018-11776
vulncheck_xdb WORKING POC
remote
https://github.com/ArunBhandarii/Apache-Struts-0Day-Exploit
metasploit WORKING POC EXCELLENT
by Man Yue Mo, hook-s3c, asoto-r7, wvu · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/struts2_namespace_ognl.rb

Nuclei Templates (1)

Apache Struts2 S2-057 - Remote Code Execution
HIGHby pikpikcu
Shodan: http.html:"apache struts" || http.title:"struts2 showcase" || http.html:"struts problem report"
FOFA: body="struts problem report" || title="struts2 showcase" || body="apache struts"

References (20)

Scores

CVSS v3 8.1
EPSS 0.9443
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Lab Environment

COMMUNITY
Community Lab
docker pull tomcat:7
docker pull tomcat:7-alpine
docker pull tomcat:7.0-alpine
+19 more repos

Details

CISA KEV 2021-11-03
VulnCheck KEV 2018-12-18
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2018-0582
Ransomware Use Confirmed
Status published
Products (11)
apache/struts 2.0.4 - 2.3.35
netapp/active_iq_unified_manager 7.3
netapp/active_iq_unified_manager 9.5
netapp/oncommand_insight
netapp/oncommand_workflow_automation
netapp/snapcenter
oracle/communications_policy_management < 12.5.0
oracle/enterprise_manager_base_platform 13.3.0.0
oracle/enterprise_manager_base_platform 13.4.0.0
oracle/mysql_enterprise_monitor < 3.4.9.4237
... and 1 more
Published Aug 22, 2018
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026