All vulnerabilities
CVE-2017-12611
Apache Struts 2.0.1 uses an unintentional expression in a Freemarker tag instead of string literal
Description
In Apache Struts 2.0.1 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.
Patch Available
Fix available through Seal Security.
No upgrade required, protect your application instantly.
Fix without upgrading
Score
9.8
Severity
Critical
Ecosystem
Java
Publish Date
October 16, 2018
Modified Date
February 16, 2024
Score Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Versions

