vulnti.work

Apache Struts Remote Code Execution Vulnerability

Critical Listed in CISA KEV
CVECVE-2018-11776
First seen2021-11-03 00:00 UTC
Disclosed2021-11-03 00:00 UTC
Last updated2026-07-18 02:00 UTC
Channel statuspending_review

Summary

Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace.

In-depth triage · Auto channel

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Affected products

  • Apache:Struts

Sources

  • CISA KEV DATABASE

Original Links

Timeline

  1. kev_added CISA KEV
  2. kev_ingest CISA KEV