CVE-2019-0230
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
- Published
- Sep 14, 2020
- Updated
- Aug 4, 2024
- Assigning CNA
- apache
- Evidence observed
- Nov 17, 2020
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
Sources
6Proof-of-concept exploit for Apache Struts 2 remote code execution vulnerability CVE-2019-0230, enabling command injection via crafted HTTP requests.
- Apache-Struts-v4Exploit
Exploit script targeting 5 Apache Struts RCE vulnerabilities (CVE-2013-2251, CVE-2017-5638, CVE-2017-9805, CVE-2018-11776, CVE-2019-0230) with PHP shell payload generation.
S2-059(CVE-2019-0230)
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.