Apache Struts 2 的 Struts 2.3.x 系列中,Struts 1 插件示例(Struts Showcase 应用)可能存在 RCE
http://struts.apache.org/docs/s2-048.html
https://cwiki.apache.org/confluence/display/WW/S2-048
> python St2-048.py
set url : http://xx.xx.xx.xx:port/integration/saveGangster.action
cmd >>: whoami
root
cmd >>: cat /etc/passwd

Struts 2.3.x 系列中,Struts 1 插件示例(Struts Showcase 应用)可能存在 RCE
谁应该阅读本文 所有 Struts 2 开发者和用户都应阅读本文
漏洞影响 使用 Struts 2 的 Struts 1 插件时可能存在 RCE
最高安全评级 高
修复建议 请阅读解决方案部分
受影响软件 带有 Struts 1 插件和 Struts 1 action 的 Struts 2.3.x
报告者 icez ,来自 Tophant Competence Center
CVE 编号 CVE-2017-9791
当使用 Struts 2 的 Struts 1 插件且其为 Struts 1 action 时,使用恶意字段值即可执行 RCE 攻击,并且该值是呈现给用户的消息的一部分,即当在 ActionMessage 类中使用不受信任的输入作为错误消息的一部分时。
始终使用资源键,而不是像下面这样将原始消息传递给 ActionMessage,切勿直接传递原始值
messages.add("msg", new ActionMessage("struts1.gangsterAdded", gform.getName()));
并且切勿这样
messages.add("msg", new ActionMessage("Gangster " + gform.getName() + " was added"));
预计不会出现向后不兼容的问题。