CVE-2017-9805: Apache Struts Deserialization of Untrusted Data Vulnerability
Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads. Required action: Apply updates per vendor instructions.
· high severity · unattributed attribution
Evidence and provenance
- Original source
- CISA KEV report ↗
- Published
- 2021-11-03T00:00:00Z
- Confidence basis
- No actor match
- Record ID
a0093baa40b1df4c33ab
Vulnerabilities
CVE-2017-9805
Use and citation
Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.