CyberSec.Space Logo
Back to CVE Browser

CVE-2021-31805

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0960%
EPSS Percentile5.62th
PublishedApr 12, 2022
Last ModifiedNov 21, 2024

Vulnerability Description

The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tagโ€™s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.

Affected Platforms (CPE)

๐Ÿ“ฆ
Apache

Struts

>= 2.0.0 and <= 2.5.29

References & Advisories

Related Vulnerabilities