← back
CVE-2021-31805observed exploitationCWE-917

Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.

82Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 85%
from disclosure to weapon3 days
Published on NVDApr 12
1st PoC+3d
VulnCheck+29d
exploitation probability
85%top 1% of all CVEs
observed exploitation
yesVulnCheck
6 public exploit(s)
The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.