EXPOSURES › CVE-2018-11776
CVE-2018-11776
HIGH ⌖ ON CISA KEV · EXPLOITEDApache Struts suffered a remote code execution vulnerability that was actively exploited in the wild, allowing attackers to execute arbitrary code on vulnerable systems.
Apache Struts contained a remote code execution vulnerability that could be triggered under specific misconfigurations, such as wildcard namespaces or missing action values. This flaw was actively exploited in the wild, enabling attackers to gain full control over affected systems. DIB organizations must ensure their Struts implementations are patched and properly configured to prevent similar compromises.
Shame score — The vulnerability was actively exploited in the wild, indicating a failure to patch or properly configure a widely used framework, leading to potential mass compromise.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace.
"Apache Struts contains a vulnerability that allows for remote code execution under two circumstances."