RULE(RULE ID:331440)

Rule General Information
Release Date: 2020-12-11
Rule Name: Apache Struts2 Remote Code Execution Vulnerability (CVE-2020-17530)
Severity:
CVE ID:
Rule Protection Details
Description: Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: http://jvn.jp/en/jp/JVN43969166/index.html
https://cwiki.apache.org/confluence/display/WW/S2-061
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://cwiki.apache.org/confluence/display/WW/S2-061