Skip to content
COOEY

FAIL › dossier

Struts

PRODUCT

· dossier confidence 20%

Apache Struts, a widely used web application framework, has a documented history of critical remote code execution vulnerabilities, highlighting significant security risks and potential compliance concerns for organizations utilizing it. These vulnerabilities underscore the need for rigorous vulnerability management and secure coding practices. The framework's open-source nature and widespread adoption necessitate careful monitoring and patching to mitigate potential exploitation.

PROFILE
CategorySoftware/FrameworkWhat they doApache Struts is an open-source web application framework for building Java EE web applications. It simplifies common development tasks such as data validation, workflow, and presentation. Websitehttps://struts.apache.org/ ↗
SECURITY POSTURE

Apache Struts has a history of severe vulnerabilities, particularly remote code execution (RCE) flaws, indicating a significant challenge in maintaining secure code. The repeated occurrence of critical vulnerabilities suggests potential weaknesses in the development lifecycle and vulnerability management processes.

Notable failures
  • CVE-2017-5638 (RCE)
  • CVE-2013-2251 (RCE)
  • CVE-2017-9805 (RCE)
  • CVE-2020-17530 (RCE)
  • CVE-2018-11776 (RCE)
Patterns: repeated unpatched RCEs; reliance on vulnerable deserialization libraries; OGNL injection vulnerabilities; insufficient input validation
FAILURE HISTORY · 5
DATEEVENTSEVSUMMARY
2022-03-25 CVE-2013-2251 high Apache Struts allowed remote attackers to execute arbitrary OGNL expressions due to improper input validation.
2021-11-03 CVE-2017-9805 high Apache Struts REST Plugin allowed remote code execution via unfiltered XML deserialization in CVE-2017-9805.
2021-11-03 CVE-2020-17530 high Apache Struts allowed remote code execution via OGNL evaluation of raw user input in tag attributes.
2021-11-03 CVE-2018-11776 high Apache Struts suffered a remote code execution vulnerability that was actively exploited in the wild, allowing attackers to execute arbitrary code on vulnerable systems.
2021-11-03 CVE-2017-5638 critical Apache Struts' file upload parser allowed attackers to execute arbitrary code remotely, actively exploited and linked to ransomware attacks.
DOSSIER SOURCES
Open questions: What specific mitigation strategies are in place to address the identified vulnerability patterns? · What is the process for identifying and patching vulnerabilities in a timely manner? · Are developers adequately trained on secure coding practices and common vulnerability types?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-20 04:41:48.450152+00:00