vulnti.work

Apache Struts Deserialization of Untrusted Data Vulnerability

Critical Listed in CISA KEV
CVECVE-2017-9805
First seen2021-11-03 00:00 UTC
Disclosed2021-11-03 00:00 UTC
Last updated2026-07-18 02:00 UTC
Channel statuspending_review

Summary

Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.

In-depth triage · Auto channel

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Affected products

  • Apache:Struts

Sources

  • CISA KEV DATABASE

Original Links

Timeline

  1. kev_added CISA KEV
  2. kev_ingest CISA KEV