Security News > 2022 > April > Critical Apache Struts RCE vulnerability wasn't fully fixed, patch now
![Critical Apache Struts RCE vulnerability wasn't fully fixed, patch now](/static/build/img/news/critical-apache-struts-rce-vulnerability-wasn-t-fully-fixed-patch-now-medium.jpg)
Apache has fixed a critical vulnerability in its vastly popular Struts project that was previously believed to have been resolved but, as it turns out, wasn't fully remedied.
Tracked as CVE-2021-31805, the critical vulnerability exists in Struts 2 versions from 2.0.0 up to and including 2.5.29.
Although Apache had resolved the 2020 bug in Struts 2.5.26, researcher Chris McCown later discovered that the applied fix was incomplete.
McCown responsibly reported to Apache that the "Double evaluation" problem could still be reproduced in Struts versions 2.5.26 and above, resulting in the assignment of CVE-2021-31805.
Users are advised to upgrade to Struts 2.5.30 or greater and to avoid using forced OGNL evaluation in the tag's attributes based on untrusted user input.
The Struts framework has had a history of critical vulnerabilities, in particular remote code execution flaws resulting from insecure OGNL use.
News URL
Related news
- VMware fixes critical vCenter RCE vulnerability, patch now (source)
- Critical Git vulnerability allows RCE when cloning repositories with submodules (CVE-2024-32002) (source)
- Critical RCE Vulnerability Discovered in Ollama AI Infrastructure Tool (source)
- GitLab Releases Patch for Critical CI/CD Pipeline Vulnerability and 13 Others (source)
- Chrome Zero-Day Alert — Update Your Browser to Patch New Vulnerability (source)
- Week in review: Veeam fixes RCE flaw in backup management platform, Patch Tuesday forecast (source)
- CISA Warns of Actively Exploited Apache Flink Security Vulnerability (source)
- TP-Link fixes critical RCE bug in popular C5400X gaming router (source)
- Exploit released for maximum severity Fortinet RCE bug, patch now (source)
- Check Point warns customers to patch VPN vulnerability under active exploitation (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-04-12 | CVE-2021-31805 | Expression Language Injection vulnerability in Apache Struts The fix issued for CVE-2020-17530 was incomplete. | 7.5 |