CVE-2018-11776
100Vexday Risk Score
Corrija agora. Ela está sob exploração confirmada pelo CISA e tem exploit funcional público.
ssvc Actcvss 8.1epss 100%
da publicação à arma1 dias
Publicada no NVD22 de ago.
1ª PoC+1d
metasploit22 de ago.
CISA KEV+1169d
probabilidade de exploração
100%top 1% das CVEs
exploração observada
simCISA + VulnCheck
44 exploit(s) público(s)
O que os fabricantes declaram (VEX)
Declarações oficiais dos fabricantes em formato CSAF/VEX: se o produto deles está afetado, já corrigido ou descartado — e por quê. É afirmação do fabricante, não juízo do Vexday.
Red Hatdocumento VEX ↗
Não afetado
1 produto — porque o código vulnerável não está presente no produto
Red Hat JBoss Fuse Service Works 6
Ação exigida pela CISAprazo federal: 2022-05-03
Apply updates per vendor instructions.
Versões
Afetadas
maven/org.apache.struts:struts2-core >= 2.0.4, <= 2.3.34; maven/org.apache.struts:struts2-core >= 2.5, <= 2.5.16
Corrigidas em
maven/org.apache.struts:struts2-core 2.3.35; maven/org.apache.struts:struts2-core 2.5.17
Pesquisado e redigido com IA a partir do advisory do fornecedor e de análises públicas, com as fontes acima. Confira sempre a versão corrigida no advisory oficial antes de agir.
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
Apache Software Foundation · Apache StrutsPoCs públicas encontradas — 44✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/45367exploitdbwww.exploit-db.com/exploits/45262não verificadoexploitdbwww.exploit-db.com/exploits/45260não verificadogithubgithub.com/mazen160/struts-pwn_CVE-2018-11776★ 303githubgithub.com/hook-s3c/CVE-2018-11776-Python-PoC★ 123githubgithub.com/649/Apache-Struts-Shodan-Exploit★ 56githubgithub.com/Ekultek/Strutter★ 21githubgithub.com/arlyone/Apache-Struts-0Day-Exploit★ 17githubgithub.com/brianwrf/S2-057-CVE-2018-11776★ 16githubgithub.com/xfox64x/CVE-2018-11776★ 15githubgithub.com/bhdresh/CVE-2018-11776★ 12githubgithub.com/jiguangsdf/CVE-2018-11776★ 10githubgithub.com/knqyf263/CVE-2018-11776★ 4githubgithub.com/tuxotron/cve-2018-11776-docker★ 3githubgithub.com/cved-sources/cve-2018-11776★ 1githubgithub.com/freshdemo/ApacheStruts-CVE-2018-11776★ 0githubgithub.com/sonpt-afk/CVE-2018-11776-FIS★ 0githubgithub.com/m4sk0ff/CVE-2018-11776★ 0githubgithub.com/jezzus/CVE-2018-11776-Python-PoC★ 0githubgithub.com/cucadili/CVE-2018-11776★ 0githubgithub.com/OzNetNerd/apche-struts-vuln-demo-cve-2018-11776★ 0vulncheckvulncheck.com/xdb/b878f3547573não verificadocve_referencepacketstormsecurity.com/files/172830/Apache-Struts-Remote-Code-Execution.htmlnão verificadovulncheckvulncheck.com/xdb/65f49344f646não verificadovulncheckvulncheck.com/xdb/306db2bfde48não verificadovulncheckvulncheck.com/xdb/80e42f4cab6bnão verificadovulncheckvulncheck.com/xdb/4ab6e9a43949não verificadovulncheckvulncheck.com/xdb/8b73fc205202não verificadocve_referencewww.exploit-db.com/exploits/45262/não verificadocve_referencewww.exploit-db.com/exploits/45367/não verificadovulncheckvulncheck.com/xdb/9047aecb9a46não verificadovulncheckvulncheck.com/xdb/df6d7ff7d1ecnão verificadovulncheckvulncheck.com/xdb/3c27e7312b41não verificadovulncheckvulncheck.com/xdb/a77791dae374não verificadovulncheckvulncheck.com/xdb/1d30c749488dnão verificadocve_referencewww.exploit-db.com/exploits/45260/não verificadovulncheckvulncheck.com/xdb/b26aba013508não verificadovulncheckvulncheck.com/xdb/7380914b3f92não verificadovulncheckvulncheck.com/xdb/e1d36328bfd4não verificadovulncheckvulncheck.com/xdb/515a9f223269não verificadovulncheckvulncheck.com/xdb/db2bd9c38413não verificadovulncheckvulncheck.com/xdb/3dd317159905não verificadovulncheckvulncheck.com/xdb/3d93850f32dcnão verificadovulncheckvulncheck.com/xdb/bc306d38c92cnão verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Referências
http://packetstormsecurity.com/files/172830/Apache-Struts-Remote-Code-Execution.htmlhttps://cwiki.apache.org/confluence/display/WW/S2-057https://github.com/hook-s3c/CVE-2018-11776-Python-PoChttps://lgtm.com/blog/apache_struts_CVE-2018-11776https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3Ehttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0012https://security.netapp.com/advisory/ntap-20180822-0001/https://security.netapp.com/advisory/ntap-20181018-0002/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-11776https://www.exploit-db.com/exploits/45260/https://www.exploit-db.com/exploits/45262/https://www.exploit-db.com/exploits/45367/