Umbra Wiki cve cve/CVE-2020-17530
Back to wiki

CVE-2020-17530 — Apache Struts Remote Code Execution Vulnerability

provenance: imported · CVE: CVE-2020-17530

CVE-2020-17530: Apache Struts Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Apache
Product Struts
Date added 2021-11-03
Due date 2022-05-03
Ransomware campaign use Unknown

Description

Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2020-17530

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2020-17530
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog