When evaluated on raw user input in tag attributes, Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation may lead to remote code execution.
Upgrade to the latest version as soon as possible