Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5038
HistorySep 08, 2017 - 6:31 a.m.

Remote Code Execution (RCE)

2017-09-0806:31:48
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21

EPSS

0.973

Percentile

99.9%

struts2-core is vulnerable to remote code execution attacks. The vulnerability exists when expression literals, or forcing expression in Freemarker tags, are used as request values. The default Freemark configuration allows ObjectConstructor, Execurt, and freemarker.template.utility.JythonRuntime to be resolved, and enabling the remote code execution weakness.