FAIL › dossier
Struts
PRODUCT· dossier confidence 20%
Apache Struts, a widely used web application framework, has a documented history of critical remote code execution vulnerabilities, highlighting significant security risks and potential compliance concerns for organizations utilizing it. These vulnerabilities underscore the need for rigorous vulnerability management and secure coding practices. The framework's open-source nature and widespread adoption necessitate careful monitoring and patching to mitigate potential exploitation.
Apache Struts has a history of severe vulnerabilities, particularly remote code execution (RCE) flaws, indicating a significant challenge in maintaining secure code. The repeated occurrence of critical vulnerabilities suggests potential weaknesses in the development lifecycle and vulnerability management processes.
- CVE-2017-5638 (RCE)
- CVE-2013-2251 (RCE)
- CVE-2017-9805 (RCE)
- CVE-2020-17530 (RCE)
- CVE-2018-11776 (RCE)
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-03-25 | CVE-2013-2251 | high | Apache Struts allowed remote attackers to execute arbitrary OGNL expressions due to improper input validation. |
| 2021-11-03 | CVE-2017-9805 | high | Apache Struts REST Plugin allowed remote code execution via unfiltered XML deserialization in CVE-2017-9805. |
| 2021-11-03 | CVE-2020-17530 | high | Apache Struts allowed remote code execution via OGNL evaluation of raw user input in tag attributes. |
| 2021-11-03 | CVE-2018-11776 | high | Apache Struts suffered a remote code execution vulnerability that was actively exploited in the wild, allowing attackers to execute arbitrary code on vulnerable systems. |
| 2021-11-03 | CVE-2017-5638 | critical | Apache Struts' file upload parser allowed attackers to execute arbitrary code remotely, actively exploited and linked to ransomware attacks. |
- Anduril Industries - Wikipedia · en.wikipedia.org
- Strut Support Systems Priv Limited - The Economic Times · economictimes.indiatimes.com
- Torrid Holdings Inc. - Resources - Investor FAQs · investors.torrid.com