CVE-2020-17530
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
- Affected products
- Apache Struts
- Apache Struts
- < 2.5.30
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 95.6% (100th percentile)
- Weakness
- CWE-917
- NVD status
- Analyzed
- Published
- 2020-12-11
CVE-2020-17530 at NVD
12 known exploits for CVE-2020-17530
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-Apache-Ecosystem
Exploit for Expression Language Injection in Apache Struts
Apache Struts forced OGNL evaluation incomplete fix
Apache Struts forced OGNL evaluation incomplete fix
Exploit for Expression Language Injection in Apache Struts
Exploit for Expression Language Injection in Apache Struts
Exploit for Expression Language Injection in Apache Struts
Exploit for Expression Language Injection in Apache Struts
Apache Struts 2 Forced Multi OGNL Evaluation Exploit
Apache Struts 2 Forced Multi OGNL Evaluation
Exploit for Expression Language Injection in Apache Struts
Apache Struts 2 Forced Multi OGNL Evaluation