Threat intelligence report · CISA KEV

CVE-2018-11776: Apache Struts Remote Code Execution Vulnerability

Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace. Required action: Apply updates per vendor instructions.

· high severity · unattributed attribution

Evidence and provenance

Original source
CISA KEV report ↗
Published
2021-11-03T00:00:00Z
Confidence basis
No actor match
Record ID
5dea5f205117eb99df9b

Vulnerabilities

CVE-2018-11776

Use and citation

Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.