When evaluated on raw user input in tag attributes, Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation may lead to remote code execution.
Mitigation / Precaution
Upgrade to the latest version as soon as possible
Automated human-like penetration testing for your web apps & APIs
Teams using Beagle Security are set up in minutes, embrace release-based CI/CD security testing and save up to 65% with timely remediation of vulnerabilities. Sign up for a free account to see what it can do for you.