EXPOSURES › CVE-2020-17530
CVE-2020-17530
HIGH ⌖ ON CISA KEV · EXPLOITEDApache Struts allowed remote code execution via OGNL evaluation of raw user input in tag attributes.
This vulnerability enabled attackers to execute arbitrary code on vulnerable systems by manipulating tag attributes, directly violating CMMC/NIST 800-171 requirements for system integrity and access control. DIB organizations must ensure all Struts-based applications are patched, as this flaw was actively exploited in the wild and represents a severe, avoidable failure in software supply chain security.
Shame score — A critical RCE flaw in a widely deployed framework that was actively exploited in the wild, demonstrating severe negligence in patch management and software supply chain security.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution.
"Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution."