Lucene search

K
cvelistApacheCVELIST:CVE-2017-12611
HistorySep 07, 2017 - 12:00 a.m.

CVE-2017-12611

2017-09-0700:00:00
apache
www.cve.org
1

9.5 High

AI Score

Confidence

High

0.973 High

EPSS

Percentile

99.9%

In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.

CNA Affected

[
  {
    "product": "Apache Struts",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "2.0.0 - 2.3.33"
      },
      {
        "status": "affected",
        "version": "2.5 - 2.5.10.1"
      }
    ]
  }
]