Skip to content
COOEY

EXPOSURES › CVE-2018-11776

CVE-2018-11776

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-11776 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

Apache Struts suffered a remote code execution vulnerability that was actively exploited in the wild, allowing attackers to execute arbitrary code on vulnerable systems.

Apache Struts contained a remote code execution vulnerability that could be triggered under specific misconfigurations, such as wildcard namespaces or missing action values. This flaw was actively exploited in the wild, enabling attackers to gain full control over affected systems. DIB organizations must ensure their Struts implementations are patched and properly configured to prevent similar compromises.

Shame score — The vulnerability was actively exploited in the wild, indicating a failure to patch or properly configure a widely used framework, leading to potential mass compromise.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Apache Struts RCE vulnerability widely recognized as critical, though provided sources lack direct commentary on vendor response or press reception.
cooey ↗ severe-fallout -0.60
Critical RCE flaw in Apache Struts, but source is a neutral NVD database entry without commentary on vendor handling.
"Apache Struts contains a vulnerability that allows for remote code execution under two circumstances."
NVD ↗ severe-fallout +0.00
No relevant content; page is a generic NVD redirect/landing page.
www.cvefind.com ↗ severe-fallout +0.00
No relevant content; generic CVE database landing page.
fortiguard.fortinet.com ↗ severe-fallout +0.00
No relevant content; generic FortiGuard PSIRT landing page.
app.opencve.io ↗ severe-fallout +0.00
No relevant content; generic OpenCVE landing page.
SentinelOne ↗ severe-fallout +0.00
No relevant content; generic SentinelOne landing page.
sam.gov ↗ severe-fallout +0.00
No relevant content; generic SAM.gov landing page.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.