CVE-2020-17530
KEVmassForced OGNL Evaluation RCE in Apache Struts 2.0.0-2.5.25
CISA: Apache Struts Remote Code Execution Vulnerability
CVE-2020-17530 is a critical (CVSS 9.8) expression-language injection flaw (CWE-917) in Apache Struts 2, in which the framework forces evaluation of OGNL expressions contained in raw, attacker-supplied user input placed into certain tag attributes. An attacker triggers it by sending crafted input (for example OGNL expressions such as %{...}) that an application passes unsanitized into a tag attribute, causing Struts to evaluate the payload as code; the network attack vector requires no authentication or user interaction. Successful exploitation yields remote code execution in the context of the hosting application server, with high impact on confidentiality, integrity, and availability. All Apache Struts 2 releases from 2.0.0 through 2.5.25 are affected, and multiple Oracle products that bundle Struts - Business Intelligence, Communications Diameter Intelligence Hub, Communications Policy Management, Communications Pricing Design Center, Financial Services Data Integration Hub, Hospitality OPERA 5, and MySQL Enterprise Monitor - are also impacted. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03 (ransomware use unknown), and EPSS assigns a 95.9% probability of exploitation within 30 days (100th percentile), although no public proof-of-concept is cataloged in this data.
What to do: Upgrade Apache Struts to 2.5.26 or later (or the corresponding legacy-branch fix, 2.3.68) per vendor instructions, and apply the relevant Oracle Critical Patch Updates for the bundled products listed above. Audit custom Struts applications for places where raw user input flows into tag attributes, since exposure depends on application usage, and review internet-facing Struts servers for indicators of OGNL injection exploitation. Because the flaw is on the CISA KEV list, apply the required vendor updates within the mandated remediation timeframe.
| Apache Struts 2 | 2.0.0 through 2.5.25 |
| Oracle Business Intelligence | — |
| Oracle Communications Diameter Intelligence Hub | — |
| Oracle Communications Policy Management | — |
| Oracle Communications Pricing Design Center | — |
| Oracle Financial Services Data Integration Hub | — |
| Oracle Hospitality OPERA 5 | — |
| Oracle MySQL Enterprise Monitor | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
- Affected
- Apache Struts
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apacheoracle
- Products
- struts, business intelligence, communications diameter intelligence hub, communications policy management, communications pricing design center, financial services data integration hub, hospitality opera 5, mysql enterprise monitor
- Weakness
- CWE-917
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H