CVE-2017-12611: vulnerability in Apache Struts
Published · Updated
84Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 87%
from disclosure to weapon0 days
Published on NVDSep 20
1st PoCSep 8
VulnCheck+2399d
exploitation probability
87%top 1% of all CVEs
observed exploitation
yesVulnCheck
7 public exploit(s)
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Not affected
5 products — because the vulnerable code is not present in the product
Red Hat Enterprise Linux 5 · Red Hat JBoss Data Virtualization 6 · Red Hat JBoss Fuse Service Works 6 · Red Hat JBoss Operations Network 3 · Red Hat Satellite 5
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.
Affected products
Apache Software Foundation · Apache Strutspublic PoCs found — 7✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/44556githubgithub.com/brianwrf/S2-053-CVE-2017-12611★ 37githubgithub.com/tcetin704/CVE-2017-12611★ 0githubgithub.com/zeynepsilao/CVE-2017-12611_Exploit★ 0vulncheckvulncheck.com/xdb/8fda6a527fabunverifiedvulncheckvulncheck.com/xdb/c0c7a67b1662unverifiedvulncheckvulncheck.com/xdb/102671f49f40unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — Apache Struts
In the same product, most dangerous first.
CVE-2017-5638CRITICALCVE-2017-5638EPSS 100.0%KEVCVE-2018-11776HIGHCVE-2018-11776EPSS 100.0%KEVCVE-2017-9805HIGHCVE-2017-9805EPSS 99.4%KEVCVE-2017-9791CRITICALCVE-2017-9791EPSS 98.9%KEVCVE-2020-17530CRITICALCVE-2020-17530EPSS 95.9%KEVCVE-2021-31805—Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.EPSS 85.4%
References
https://kb.netapp.com/support/s/article/ka51A000000CgttQAC/NTAP-20170911-0001https://struts.apache.org/docs/s2-053.htmlhttp://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-003.txthttp://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.htmlhttp://www.securityfocus.com/bid/100829