Apache Struts RCE

Published on 01 Oct 2021
Vulnerability

When evaluated on raw user input in tag attributes, Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation may lead to remote code execution.

Mitigation / Precaution

Upgrade to the latest version as soon as possible

Prathap
Written by
Co-founder, Director

Prathap has around 20 years of experience and has worked on various projects in leading companies like Hitachi, Toshiba, Schneider Electric, ABB, Panasonic, and MicroFuzzy. His expertise lies in architecting, designing, and developing secure projects covering various aspects of software development, processes, and methodology.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo