Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-17530

Опубликовано: 08 дек. 2020
Источник: redhat
CVSS3: 8.1

Описание

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.

A flaw was found in the Apache Struts frameworks. When forced, some of the tag's attributes perform a double evaluation if a developer applies forced OGNL evaluation by using the %{...} syntax. Using a forced OGNL evaluation on untrusted user input allows an attacker to perform remote code execution and security degradation. The highest threat from this vulnerability is to data confidentiality, integrity as well as system availability.

Отчет

Apache Struts2 is not compiled, shipped, used, or enabled in Red Hat products. As such, any CVE against Apache Struts2 does not impact currently supported Red Hat products. This statement was last revised on 1 Sept 2020. Previous statement example: https://bugzilla.redhat.com/show_bug.cgi?id=1469265

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat CodeReady Studio 12strutsNot affected
Red Hat JBoss Enterprise Application Platform 6strutsNot affected
Red Hat JBoss Fuse 6struts-coreNot affected
Red Hat JBoss Fuse Service Works 6strutsNot affected
Red Hat JBoss Operations Network 3strutsNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1905645struts2: using forced OGNL evaluation on untrusted user input can lead to a RCE and security degradation

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 5 лет назад

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.

CVSS3: 9.8
nvd
около 5 лет назад

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.

CVSS3: 9.8
debian
около 5 лет назад

Forced OGNL evaluation, when evaluated on raw user input in tag attrib ...

CVSS3: 9.8
github
почти 4 года назад

Remote code execution in Apache Struts

CVSS3: 9.8
fstec
около 5 лет назад

Уязвимость программной платформы Apache Struts, существующая из-за некорректной обработки выражений Object Graph Navigation Language, позволяющая нарушителю выполнить произвольный код

8.1 High

CVSS3