漏洞描述
Apache Struts 2.1.x and 2.3.x with the Struts 1 plugin might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.oracle.comhttp://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html↗struts.apache.orghttp://struts.apache.org/docs/s2-048.html↗web.archive.orghttp://web.archive.org/web/20211207175819/https://securitytracker.com/id/1038838↗www.securitytracker.comhttp://www.securitytracker.com/id/1038838↗security.netapp.comhttps://security.netapp.com/advisory/ntap-20180706-0002/↗