CVE-2021-31805
The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.
- Affected products
- Apache Struts
- Apache Struts
- ≤ 2.5.29
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 85.4% (100th percentile)
- Weakness
- CWE-917
- NVD status
- Modified
- Published
- 2022-04-12
Workaround
Avoid using forced OGNL evaluation on untrusted user input, and/or upgrade to Struts 2.5.30 which checks if expression evaluation won’t lead to the double evaluation. Please read our Security Bulletin S2-062 for more details.
CVE-2021-31805 at NVD
7 known exploits for CVE-2021-31805
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Expression Language Injection in Apache Struts
Exploit for Expression Language Injection in Apache Struts
Exploit for Expression Language Injection in Apache Struts
Exploit for Expression Language Injection in Apache Struts
Exploit for Expression Language Injection in Apache Struts
Exploit for Expression Language Injection in Apache Struts
Exploit for Expression Language Injection in Apache Struts