CVE-2020-17530
CRITICAL KEV NUCLEIApache Struts 2 Forced Multi OGNL Evaluation
Title source: metasploitDescription
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
Exploits (14)
nomisec
WORKING POC
7 stars
by fengziHK · remote
https://github.com/fengziHK/CVE-2020-17530-strust2-061
nomisec
WORKING POC
4 stars
by CyborgSecurity · remote
https://github.com/CyborgSecurity/CVE-2020-17530
metasploit
WORKING POC
EXCELLENT
by Spencer McIntyre, Matthias Kaiser, Alvaro Muñoz, ka1n4t · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/struts2_multi_eval_ognl.rb
Nuclei Templates (1)
Apache Struts 2.0.0-2.5.25 - Remote Code Execution
CRITICALby pikpikcu
Shodan:
http.html:"apache struts" || http.title:"struts2 showcase" || http.html:"struts problem report"
FOFA:
body="struts problem report" || title="struts2 showcase" || body="apache struts"
References (12)
Scores
CVSS v3
9.8
EPSS
0.9438
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2021-11-03
VulnCheck KEV
2021-04-12
InTheWild.io
2021-07-23
ENISA EUVD
EUVD-2022-1073
CWE
CWE-917
Status
published
Products (14)
apache/struts
2.0.0 - 2.5.30
oracle/business_intelligence
12.2.1.3.0
oracle/business_intelligence
12.2.1.4.0
oracle/communications_diameter_intelligence_hub
8.0.0
oracle/communications_diameter_intelligence_hub
8.1.0
oracle/communications_diameter_intelligence_hub
8.2.0
oracle/communications_diameter_intelligence_hub
8.2.3
oracle/communications_policy_management
12.5.0
oracle/communications_pricing_design_center
12.0.0.3.0
oracle/financial_services_data_integration_hub
8.0.3
... and 4 more
Published
Dec 11, 2020
KEV Added
Nov 03, 2021
Tracked Since
Feb 18, 2026