Apache Struts RCE

By
Prathap
Published on
01 Oct 2021
Vulnerability

When evaluated on raw user input in tag attributes, Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation may lead to remote code execution.

Mitigation / Precaution

Upgrade to the latest version as soon as possible


Written by
Prathap
Prathap
Co-founder, Director
Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 10 days