
Apache Struts2 S2-062(CVE-2021-31805)远程代码执行批量检测(无利用)
Vulnerability Information Apache Struts is a free, open-source MVC framework for creating elegant, modern Java web applications. It favors convention over configuration, can be extended using a plugin architecture, and ships with plugins that support REST, AJAX, and JSON. Recently, Apache officially published the security advisory for the S2-062 remote code execution vulnerability, with the vulnerability ID CVE-2021-31805:
The fix released for CVE-2020-17530 is incomplete. Therefore, from Apache Struts 2.0.0 to 2.5.29, if developers apply forced OGNL evaluation by using the %{…} syntax, some tag attributes can still perform double evaluation. Using forced OGNL evaluation on untrusted user input may lead to a remote code execution vulnerability. The vulnerability ID CVE-2022-22954 affects the following versions: Struts 2.0.0 - Struts 2.5.29