CVE-2020-17530

CRITICAL KEV NUCLEI

Apache Struts 2 Forced Multi OGNL Evaluation

Title source: metasploit

Description

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.

Exploits (14)

nomisec WORKING POC 65 stars
by ka1n4t · remote
https://github.com/ka1n4t/CVE-2020-17530
nomisec WORKING POC 48 stars
by wuzuowei · remote
https://github.com/wuzuowei/CVE-2020-17530
nomisec WORKING POC 29 stars
by Al1ex · remote
https://github.com/Al1ex/CVE-2020-17530
nomisec WORKING POC 7 stars
by fengziHK · remote
https://github.com/fengziHK/CVE-2020-17530-strust2-061
nomisec STUB 5 stars
by uzzzval · poc
https://github.com/uzzzval/CVE-2020-17530
nomisec WORKING POC 4 stars
by CyborgSecurity · remote
https://github.com/CyborgSecurity/CVE-2020-17530
nomisec STUB 1 stars
by secpool2000 · poc
https://github.com/secpool2000/CVE-2020-17530
nomisec WORKING POC
by fatkz · remote
https://github.com/fatkz/CVE-2020-17530
nomisec WORKING POC
by nth347 · poc
https://github.com/nth347/CVE-2020-17530
nomisec WORKING POC
by keyuan15 · remote
https://github.com/keyuan15/CVE-2020-17530
nomisec WORKING POC
by killmonday · remote
https://github.com/killmonday/CVE-2020-17530-s2-061
nomisec WORKING POC
by ludy-dev · remote
https://github.com/ludy-dev/freemarker_RCE_struts2_s2-061
metasploit WORKING POC EXCELLENT
by Spencer McIntyre, Matthias Kaiser, Alvaro Muñoz, ka1n4t · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/struts2_multi_eval_ognl.rb

Nuclei Templates (1)

Apache Struts 2.0.0-2.5.25 - Remote Code Execution
CRITICALby pikpikcu
Shodan: http.html:"apache struts" || http.title:"struts2 showcase" || http.html:"struts problem report"
FOFA: body="struts problem report" || title="struts2 showcase" || body="apache struts"

Scores

CVSS v3 9.8
EPSS 0.9438
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-04-12
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2022-1073
CWE
CWE-917
Status published
Products (14)
apache/struts 2.0.0 - 2.5.30
oracle/business_intelligence 12.2.1.3.0
oracle/business_intelligence 12.2.1.4.0
oracle/communications_diameter_intelligence_hub 8.0.0
oracle/communications_diameter_intelligence_hub 8.1.0
oracle/communications_diameter_intelligence_hub 8.2.0
oracle/communications_diameter_intelligence_hub 8.2.3
oracle/communications_policy_management 12.5.0
oracle/communications_pricing_design_center 12.0.0.3.0
oracle/financial_services_data_integration_hub 8.0.3
... and 4 more
Published Dec 11, 2020
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026