CVE-2017-9791
KEVlargeUnauthenticated RCE via Improper Input Validation in Apache Struts 1 Plugin
CISA: Apache Struts 1 Improper Input Validation Vulnerability
CVE-2017-9791 is an improper input validation flaw (CWE-20) in the Struts 1 plugin shipped with Apache Struts 2.1.x and 2.3.x. When a user-supplied field value is passed as a raw message to ActionMessage, it is evaluated as an expression, allowing an unauthenticated attacker to achieve remote code execution with the privileges of the Java web application. Organizations running Struts 2.1.x/2.3.x applications with the Struts 1 plugin enabled are affected, and Oracle has separately shipped patches for Struts bundled in its products. The flaw is listed in CISA's Known Exploited Vulnerabilities Catalog (added 2022-02-10) and carries a 98.9% EPSS score (100th percentile), indicating active, widespread exploitation, though no public proof-of-concept is catalogued.
What to do: Apply updates per vendor instructions as required by CISA by upgrading Struts 2.1.x/2.3.x to a patched release and, where feasible, disabling or removing the Struts 1 plugin; audit application code for ActionMessage calls that pass unvalidated user input as raw messages. For Oracle products that bundle Struts, apply Oracle's Struts-related security patches. Prioritize internet-facing applications given confirmed in-the-wild exploitation (KEV) and the near-certain near-term exploitation probability (EPSS 98.9%).
| Apache Struts 2 (with Struts 1 plugin enabled) | 2.1.x, 2.3.x |
| Apache Struts 1 (legacy framework, per CISA affected listing) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
- Affected
- Apache Struts 1
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apache
- Products
- struts
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H