Apache Struts Remote Code Execution Vulnerability
Critical Listed in CISA KEV
Summary
Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- Apache:Struts
Sources
- CISA KEV DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2018-11776 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV