Lucene search

K
osvGoogleOSV:GHSA-V8J6-6C2R-R27C
HistoryApr 13, 2022 - 12:00 a.m.

Expression Language Injection in Apache Struts

2022-04-1300:00:30
Google
osv.dev
62

0.973 High

EPSS

Percentile

99.9%

The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{…} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.