ZeroHour
Security Affairspublished ()ingested @securityaffairs

CVE-2021-31805 RCE bug in Apache Struts was finally patched

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-17530
Forced OGNL Evaluation RCE in Apache Struts 2.0.0-2.5.25

CVE-2020-17530 is a critical (CVSS 9.8) expression-language injection flaw (CWE-917) in Apache Struts 2, in which the framework forces evaluation of OGNL expressions contained in raw, attacker-supplied user input placed into certain tag attributes. An attacker triggers it by sending crafted input (for example OGNL expressions such as %{...}) that an application passes unsanitized into a tag attribute, causing Struts to evaluate the payload as code; the network attack vector requires no authentication or user interaction. Successful exploitation yields remote code execution in the context of the hosting application server, with high impact on confidentiality, integrity, and availability. All Apache Struts 2 releases from 2.0.0 through 2.5.25 are affected, and multiple Oracle products that bundle Struts - Business Intelligence, Communications Diameter Intelligence Hub, Communications Policy Management, Communications Pricing Design Center, Financial Services Data Integration Hub, Hospitality OPERA 5, and MySQL Enterprise Monitor - are also impacted. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03 (ransomware use unknown), and EPSS assigns a 95.9% probability of exploitation within 30 days (100th percentile), although no public proof-of-concept is cataloged in this data.

Do: Upgrade Apache Struts to 2.5.26 or later (or the corresponding legacy-branch fix, 2.3.68) per vendor instructions, and apply the relevant Oracle Critical Patch Updates for the bundled products listed above. Audit custom Struts applications for places where raw user input flows into tag attributes, since exposure depends on application usage, and review internet-facing Struts servers for indicators of OGNL injection exploitation. Because the flaw is on the CISA KEV list, apply the required vendor updates within the mandated remediation timeframe.

9.896% KEV
  • Apache Struts 2 2.0.0 through 2.5.25
  • Oracle Business Intelligence
  • Oracle Communications Diameter Intelligence Hub
  • +5 more
masson the order of 10^5-10^6 internet-exposed Apache Struts deployments, plus an unquantified embedded base in Oracle products
CVE-2021-31805
The fix issued for CVE-2020-17530 was incomplete.

The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.

NVD description · AI analysis pending
9.885%
  • apache struts
Full article399 words · extracted from securityaffairs.com · click to collapse

Apache addressed a critical flaw in Apache Struts RCE that was linked to a previous issue that was not properly fixed.

Apache Struts is an open-source web application framework for developing Java EE web applications.

The Apache Software Foundation urges organizations to address a vulnerability, tracked as CVE-2021-31805, affecting Struts versions ranging 2.0.0 to 2.5.29. An attacker could trigger this vulnerability to take control of an affected system.

According to the advisory published by Apache, the issue addressed by the organization is a critical flaw in Apache Struts linked to a previous OGNL Injection flaw (CVE-2020-17530) that wasn’t properly fixed.

The remote code execution flaw, tracked as CVE-2020-17530, resides in forced OGNL evaluation when evaluated on raw user input in tag attributes.

“Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution – similar to S2-059.” reads the advisory published by the Apache Software Foundation“Some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.”

Upon forcing OGNL evaluation using the %{…} syntax, tag’s attributes could perform double evaluation. Forced OGNL evaluation on untrusted input it is possible to achieve remote code execution.

“The fix issued for CVE-2020-17530 (S2-061) was incomplete. Still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{…} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.” reads the advisory published by Apache.

CISA also published a security advisory for Struts 2 recommending organizations to upgrade their installs.

Apache advisory recommends avoiding using forced OGNL evaluation on untrusted user input, and/or upgrade to Struts 2.5.30 or greater which checks if expression evaluation won’t lead to the double evaluation.

Please vote for Security Affairs as the best European Cybersecurity Blogger Awards 2022 – VOTE FOR YOUR WINNERS
Vote for me in the sections “The Underdogs – Best Personal (non-commercial) Security Blog” and “The Tech Whizz – Best Technical Blog” and others of your choice.
To nominate, please visit: 
https://docs.google.com/forms/d/e/1FAIpQLSfxxrxICiMZ9QM9iiPuMQIC-IoM-NpQMOsFZnJXrBQRYJGCOw/viewform  

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Apache)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/130173/security/critical-apache-struts-rce-flaw.html