Sploitus

CVE-2021-31805

7 known exploits for CVE-2021-31805

The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.

Affected products
Apache Struts
Apache Struts
≤ 2.5.29
CVSS 3.1
9.8 CRITICAL
EPSS
85.4% (100th percentile)
Weakness
CWE-917
NVD status
Modified
Published
2022-04-12

Workaround

Avoid using forced OGNL evaluation on untrusted user input, and/or upgrade to Struts 2.5.30 which checks if expression evaluation won’t lead to the double evaluation. Please read our Security Bulletin S2-062 for more details.

CVE-2021-31805 at NVD
Authoritative description, scoring and affected products

7 known exploits for CVE-2021-31805

Proof-of-concept code and exploit modules indexed by Sploitus