CVE-2020-17530
Apache Struts Remote Code Execution Vulnerability
- Published
- Dec 11, 2020
- Updated
- Oct 21, 2025
- Assigning CNA
- apache
- Evidence observed
- Nov 3, 2021
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
Sources
12S2-061 CVE-2020-17530
- CVE-2020-17530Exploit
Python exploit for OGNL injection (CVE-2020-17530) in Apache Struts2/Tomcat, enabling remote command execution on vulnerable targets.
- CVE-2020-17530Exploit
Python-based exploit for Struts2 S2-061 (CVE-2020-17530) remote command execution vulnerability. Supports single URL, file-based scanning, proxy, and output logging.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.