漏洞描述
Apache Struts2 S2-062 is vulnerable to remote code execution. The fix issued for CVE-2020-17530 (S2-061) was incomplete, meaning some of the tag's attributes could still perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
cwiki.apache.orghttps://cwiki.apache.org/confluence/display/WW/S2-062↗github.comhttps://github.com/Axx8/Struts2_S2-062_CVE-2021-31805↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2021-31805↗www.openwall.comhttp://www.openwall.com/lists/oss-security/2022/04/12/6↗security.netapp.comhttps://security.netapp.com/advisory/ntap-20220420-0001/↗