漏洞描述
Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1 uses an unintentional expression in a Freemarker tag instead of string literals, which makes it susceptible to remote code execution attacks.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
struts.apache.orghttps://struts.apache.org/docs/s2-053.html↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2017-12611↗kb.netapp.comhttps://kb.netapp.com/support/s/article/ka51A000000CgttQAC/NTAP-20170911-0001↗www.arubanetworks.comhttp://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-003.txt↗www.oracle.comhttp://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html↗