CVE-2018-11776
100Vexday Risk Score
Corrige ahora. Ella está bajo explotación confirmada por CISA y tiene exploit funcional público.
ssvc Actcvss 8.1epss 100%
de la publicación al arma1 días
Publicada en NVD22 ago
1ª PoC+1d
metasploit22 ago
CISA KEV+1169d
probabilidad de explotación
100%top 1% de las CVE
explotación observada
síCISA + VulnCheck
41 exploit(s) público(s)
Acción exigida por CISAplazo federal: 2022-05-03
Apply updates per vendor instructions.
Versiones
Afectadas
maven/org.apache.struts:struts2-core >= 2.0.4, <= 2.3.34; maven/org.apache.struts:struts2-core >= 2.5, <= 2.5.16
Corregidas en
maven/org.apache.struts:struts2-core 2.3.35; maven/org.apache.struts:struts2-core 2.5.17
Investigado y redactado con IA a partir del advisory del fabricante y análisis públicos, con las fuentes citadas. Verifica siempre la versión corregida en el advisory oficial antes de actuar.
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Apache Software Foundation · Apache StrutsPoCs públicas encontradas — 41✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/45367exploitdbwww.exploit-db.com/exploits/45260no verificadoexploitdbwww.exploit-db.com/exploits/45262no verificadogithubgithub.com/mazen160/struts-pwn_CVE-2018-11776★ 303githubgithub.com/hook-s3c/CVE-2018-11776-Python-PoC★ 123githubgithub.com/649/Apache-Struts-Shodan-Exploit★ 56githubgithub.com/Ekultek/Strutter★ 21githubgithub.com/brianwrf/S2-057-CVE-2018-11776★ 16githubgithub.com/arlyone/Apache-Struts-0Day-Exploit★ 16githubgithub.com/xfox64x/CVE-2018-11776★ 15githubgithub.com/bhdresh/CVE-2018-11776★ 12githubgithub.com/jiguangsdf/CVE-2018-11776★ 10githubgithub.com/knqyf263/CVE-2018-11776★ 4githubgithub.com/tuxotron/cve-2018-11776-docker★ 3githubgithub.com/cved-sources/cve-2018-11776★ 1githubgithub.com/m4sk0ff/CVE-2018-11776★ 0githubgithub.com/freshdemo/ApacheStruts-CVE-2018-11776★ 0githubgithub.com/sonpt-afk/CVE-2018-11776-FIS★ 0githubgithub.com/OzNetNerd/apche-struts-vuln-demo-cve-2018-11776★ 0githubgithub.com/jezzus/CVE-2018-11776-Python-PoC★ 0githubgithub.com/cucadili/CVE-2018-11776★ 0cve_referencewww.exploit-db.com/exploits/45367/no verificadocve_referencewww.exploit-db.com/exploits/45260/no verificadocve_referencewww.exploit-db.com/exploits/45262/no verificadovulncheckvulncheck.com/xdb/3c27e7312b41no verificadovulncheckvulncheck.com/xdb/df6d7ff7d1ecno verificadovulncheckvulncheck.com/xdb/9047aecb9a46no verificadovulncheckvulncheck.com/xdb/8b73fc205202no verificadovulncheckvulncheck.com/xdb/4ab6e9a43949no verificadovulncheckvulncheck.com/xdb/80e42f4cab6bno verificadovulncheckvulncheck.com/xdb/306db2bfde48no verificadovulncheckvulncheck.com/xdb/65f49344f646no verificadovulncheckvulncheck.com/xdb/1d30c749488dno verificadovulncheckvulncheck.com/xdb/b26aba013508no verificadovulncheckvulncheck.com/xdb/7380914b3f92no verificadovulncheckvulncheck.com/xdb/e1d36328bfd4no verificadovulncheckvulncheck.com/xdb/515a9f223269no verificadovulncheckvulncheck.com/xdb/db2bd9c38413no verificadovulncheckvulncheck.com/xdb/3dd317159905no verificadovulncheckvulncheck.com/xdb/3d93850f32dcno verificadocve_referencepacketstormsecurity.com/files/172830/Apache-Struts-Remote-Code-Execution.htmlno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
http://packetstormsecurity.com/files/172830/Apache-Struts-Remote-Code-Execution.htmlhttps://cwiki.apache.org/confluence/display/WW/S2-057https://github.com/hook-s3c/CVE-2018-11776-Python-PoChttps://lgtm.com/blog/apache_struts_CVE-2018-11776https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3Ehttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0012https://security.netapp.com/advisory/ntap-20180822-0001/https://security.netapp.com/advisory/ntap-20181018-0002/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-11776https://www.exploit-db.com/exploits/45260/https://www.exploit-db.com/exploits/45262/https://www.exploit-db.com/exploits/45367/