ZeroHour
Security Affairspublished ()ingested @securityaffairs1

Apache Software Foundation fixes code execution flaw in Apache Struts 2

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-0230
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.

Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.

NVD description · AI analysis pending
9.897% PoC ×2
  • apache struts
  • apache communications policy management
  • apache financial services data integration hub
  • +1 more
CVE-2020-17530
Forced OGNL Evaluation RCE in Apache Struts 2.0.0-2.5.25

CVE-2020-17530 is a critical (CVSS 9.8) expression-language injection flaw (CWE-917) in Apache Struts 2, in which the framework forces evaluation of OGNL expressions contained in raw, attacker-supplied user input placed into certain tag attributes. An attacker triggers it by sending crafted input (for example OGNL expressions such as %{...}) that an application passes unsanitized into a tag attribute, causing Struts to evaluate the payload as code; the network attack vector requires no authentication or user interaction. Successful exploitation yields remote code execution in the context of the hosting application server, with high impact on confidentiality, integrity, and availability. All Apache Struts 2 releases from 2.0.0 through 2.5.25 are affected, and multiple Oracle products that bundle Struts - Business Intelligence, Communications Diameter Intelligence Hub, Communications Policy Management, Communications Pricing Design Center, Financial Services Data Integration Hub, Hospitality OPERA 5, and MySQL Enterprise Monitor - are also impacted. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03 (ransomware use unknown), and EPSS assigns a 95.9% probability of exploitation within 30 days (100th percentile), although no public proof-of-concept is cataloged in this data.

Do: Upgrade Apache Struts to 2.5.26 or later (or the corresponding legacy-branch fix, 2.3.68) per vendor instructions, and apply the relevant Oracle Critical Patch Updates for the bundled products listed above. Audit custom Struts applications for places where raw user input flows into tag attributes, since exposure depends on application usage, and review internet-facing Struts servers for indicators of OGNL injection exploitation. Because the flaw is on the CISA KEV list, apply the required vendor updates within the mandated remediation timeframe.

9.896% KEV
  • Apache Struts 2 2.0.0 through 2.5.25
  • Oracle Business Intelligence
  • Oracle Communications Diameter Intelligence Hub
  • +5 more
masson the order of 10^5-10^6 internet-exposed Apache Struts deployments, plus an unquantified embedded base in Oracle products
Full article417 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 09, 2020

The Apache Software Foundation addressed a possible remote code execution vulnerability in Struts 2 related to the OGNL technology. 

The Apache Software Foundation has released a security update to address a “possible remote code execution” flaw in Struts 2 that is related to the OGNL technology. 

The remote code execution flaw, tracked as CVE-2020-17530, resides in forced OGNL evaluation when evaluated on raw user input in tag attributes.

“Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution – similar to S2-059.” reads the advisory published by the Apache Software Foundation. “Some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.”

Upon forcing OGNL evaluation using the %{…} syntax, tag’s attributes could perform double evaluation. Forced OGNL evaluation on untrusted input it is possible to achieve remote code execution.

In August, security researchers discovered a PoC code and exploit available on GitHub that that can be used to trigger the security vulnerabilities in Apache Struts 2. One of the two flaws was the CVE-2019-0230 is similar to CVE-2020-17530.

The CVE-2019-0230 could be triggered when a threat actor sends a malicious Object-Graph Navigation Language (OGNL) expression that can result in a remote code-execution in the context of the affected application.

Depending on the privileges associated with the affected application, an attacker could perform multiple malicious activities, such as install applications; modify or delete data, or create new admin accounts.

The Apache Software Foundation also provided a workaround for the CVE-2020-17530 flaw, developers should make sure that forced OGNL evaluation is not used on untrusted input. 

The flaw affects Struts 2.0.0 to Struts 2.5.25 and was addressed with the release of Struts 2.5.26.

The Cybersecurity and Infrastructure Security Agency (CISA) also published a security advisory for the CVE-2020-17530 flaw.

“The Apache Software Foundation has released a security update to address a vulnerability in Apache Struts versions 2.0.0 to 2.5.25. A remote attacker could exploit this vulnerability to take control of an affected system.” states the CISA’s advisory.

“The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review Apache Security Bulletin S2-061 and Apache security advisory for CVE-2020-17530 and apply the necessary update or workaround.”

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Struts 2)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/112089/security/struts-2-flaw.html