VulnerabilityModified
CVE-2017-12611
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.
CRITICAL 9.8EPSS 87.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 87.1%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 87.12% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- apache/struts
- Source
- security@apache.org
References
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-003.txtMitigation, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/100829Third Party Advisory, VDB Entry
- https://kb.netapp.com/support/s/article/ka51A000000CgttQAC/NTAP-20170911-0001Patch, Third Party Advisory
- https://struts.apache.org/docs/s2-053.htmlExploit, Vendor Advisory
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-003.txtMitigation, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/100829Third Party Advisory, VDB Entry
- https://kb.netapp.com/support/s/article/ka51A000000CgttQAC/NTAP-20170911-0001Patch, Third Party Advisory
- https://struts.apache.org/docs/s2-053.htmlExploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.