Launch Week Day 1: Announcing Security Design Review
HIGH 8.1 Maven KEV

Apache Struts vulnerable to remote command execution (RCE) due to improper input validation

GHSA-cr6j-3jp9-rw65 · CVE-2018-11776

Published · Modified

Description

Apache Struts contains a Remote Code Execution when using results with no namespace and it's upper actions have no or wildcard namespace. The same flaw exists when using a url tag with no value, action set, and it's upper actions have no or wildcard namespace.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes