Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 85%
from disclosure to weapon3 days
Published on NVDApr 12
1st PoC+3d
VulnCheck+29d
exploitation probability
85%top 1% of all CVEs
observed exploitation
yesVulnCheck
6 public exploit(s)
The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.
Affected products
Apache Software Foundation · Apache Strutspublic PoCs found — 6
vulncheckvulncheck.com/xdb/d2fdeaa69784unverifiedvulncheckvulncheck.com/xdb/093ed7b6c682unverifiedvulncheckvulncheck.com/xdb/34a0b425a90cunverifiedvulncheckvulncheck.com/xdb/36ffb3b771eaunverifiedvulncheckvulncheck.com/xdb/61bff6d74e54unverifiedvulncheckvulncheck.com/xdb/cb89472f97e9unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.