CVE-2021-31805observed exploitationCWE-917

CVE-2021-31805: vulnerability in Apache Struts

Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.

Published · Updated

82Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 85%
from disclosure to weapon3 days
Published on NVDApr 12
1st PoC+3d
VulnCheck+29d
exploitation probability
85%top 1% of all CVEs
observed exploitation
yesVulnCheck
6 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Not affected
3 products — because the vulnerable code is not present in the product
Red Hat JBoss Fuse 6 · Red Hat JBoss Fuse Service Works 6 · Red Hat JBoss Operations Network 3
The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.