CVE-2018-11776

HIGH KEV RANSOMWARE NUCLEI

Apache Struts 2 Namespace Redirect OGNL Injection

Title source: metasploit

Description

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.

Exploits (28)

github WRITEUP 3,480 stars
by qazbnm456 · poc
https://github.com/qazbnm456/awesome-cve-poc/tree/master/CVE-2018-11776.md
nomisec WORKING POC 303 stars
by mazen160 · remote
https://github.com/mazen160/struts-pwn_CVE-2018-11776
nomisec WORKING POC 123 stars
by hook-s3c · remote
https://github.com/hook-s3c/CVE-2018-11776-Python-PoC
nomisec WORKING POC 55 stars
by 649 · remote
https://github.com/649/Apache-Struts-Shodan-Exploit
nomisec WORKING POC 21 stars
by Ekultek · remote
https://github.com/Ekultek/Strutter
nomisec WORKING POC 16 stars
by brianwrf · remote
https://github.com/brianwrf/S2-057-CVE-2018-11776
nomisec WRITEUP 15 stars
by xfox64x · remote
https://github.com/xfox64x/CVE-2018-11776
nomisec WORKING POC 15 stars
by arlyone · poc
https://github.com/arlyone/Apache-Struts-0Day-Exploit
github WRITEUP 14 stars
by xbl3 · poc
https://github.com/xbl3/awesome-cve-poc_qazbnm456/tree/master/CVE-2018-11776.md
nomisec WORKING POC 12 stars
by bhdresh · remote
https://github.com/bhdresh/CVE-2018-11776
nomisec SCANNER 10 stars
by jiguangsdf · remote
https://github.com/jiguangsdf/CVE-2018-11776
nomisec WORKING POC 4 stars
by knqyf263 · remote
https://github.com/knqyf263/CVE-2018-11776
github WRITEUP 3 stars
by HxDDD · poc
https://github.com/HxDDD/CVE-PoC/tree/main/Apache/(RCE) CVE-2018-11776.md
nomisec WORKING POC 3 stars
by tuxotron · remote
https://github.com/tuxotron/cve-2018-11776-docker
nomisec STUB 1 stars
by cved-sources · poc
https://github.com/cved-sources/cve-2018-11776
nomisec WORKING POC
by m4sk0ff · remote
https://github.com/m4sk0ff/CVE-2018-11776
nomisec WORKING POC
by freshdemo · remote
https://github.com/freshdemo/ApacheStruts-CVE-2018-11776
gitlab WORKING POC
by drent · poc
https://gitlab.com/drent/S2-057-CVE-2018-11776
nomisec WORKING POC
by sonpt-afk · remote
https://github.com/sonpt-afk/CVE-2018-11776-FIS
nomisec WORKING POC
by OzNetNerd · poc
https://github.com/OzNetNerd/apche-struts-vuln-demo-cve-2018-11776
nomisec WRITEUP
by cucadili · poc
https://github.com/cucadili/CVE-2018-11776
exploitdb WORKING POC
by hook-s3c · pythonremotemultiple
https://www.exploit-db.com/exploits/45262
metasploit WORKING POC EXCELLENT
by Man Yue Mo, hook-s3c, asoto-r7, wvu · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/struts2_namespace_ognl.rb
exploitdb WORKING POC
by Mazin Ahmed · pythonremotelinux
https://www.exploit-db.com/exploits/45260
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/45367
vulncheck_xdb WORKING POC
remote
https://github.com/ArunBhandarii/Apache-Struts-0Day-Exploit

Nuclei Templates (1)

Apache Struts2 S2-057 - Remote Code Execution
HIGHby pikpikcu
Shodan: http.html:"apache struts" || http.title:"struts2 showcase" || http.html:"struts problem report"
FOFA: body="struts problem report" || title="struts2 showcase" || body="apache struts"

References (20)

Scores

CVSS v3 8.1
EPSS 0.9443
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2021-11-03
VulnCheck KEV 2018-12-18
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2018-0582
Ransomware Use Confirmed

Classification

Status published

Affected Products (11)

apache/struts < 2.3.35
netapp/active_iq_unified_manager
netapp/active_iq_unified_manager
netapp/oncommand_insight
netapp/oncommand_workflow_automation
netapp/snapcenter
oracle/communications_policy_management < 12.5.0
oracle/enterprise_manager_base_platform
oracle/enterprise_manager_base_platform
oracle/mysql_enterprise_monitor < 3.4.9.4237
org.apache.struts/struts2-core < 2.3.35Maven

Timeline

Published Aug 22, 2018
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026