Skip to content
COOEY

EXPOSURES › CVE-2020-17530

CVE-2020-17530

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-17530 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

Apache Struts allowed remote code execution via OGNL evaluation of raw user input in tag attributes.

This vulnerability enabled attackers to execute arbitrary code on vulnerable systems by manipulating tag attributes, directly violating CMMC/NIST 800-171 requirements for system integrity and access control. DIB organizations must ensure all Struts-based applications are patched, as this flaw was actively exploited in the wild and represents a severe, avoidable failure in software supply chain security.

Shame score — A critical RCE flaw in a widely deployed framework that was actively exploited in the wild, demonstrating severe negligence in patch management and software supply chain security.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution.

SENTIMENT · TRUSTED SOURCES
synthesis neutral +0.00
No security press or authority coverage found for CVE-2020-17530 in the provided sources; sources are unrelated or empty.
cooey ↗ neutral +0.00
Neutral; NVD entry only states the technical vulnerability without commentary on vendor response.
"Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution."
www.nbcnews.com ↗ neutral +0.00
Irrelevant; NBC News article is about a racial slur incident, not the Apache vulnerability.
NVD ↗ neutral +0.00
Irrelevant; NVD page is for a different CVE (CVE-2026-56164) and contains no Apache Struts commentary.
sam.gov ↗ neutral +0.00
Irrelevant; SAM.gov page contains no security press or authority commentary on the vulnerability.
app.opencve.io ↗ neutral +0.00
Irrelevant; OpenCVE page is a general CVE search tool with no specific commentary on Apache Struts.
people.com ↗ neutral +0.00
Irrelevant; People.com article is about a TV show intruder, not the Apache vulnerability.
www.cvefind.com ↗ neutral +0.00
Irrelevant; CVE Find page is a general vulnerability database with no specific commentary on Apache Struts.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.