Record summary
A quick snapshot of what this page covers.
Vulnerability status
How serious this vulnerability is and whether it is known to be exploited.
- CVE ID
- CVE-2018-11776
- Vendor/project
- Apache
- Product
- Struts
- Vulnerability name
- Apache Struts Remote Code Execution Vulnerability
- Date added
- 2021-11-03
- Due date
- 2022-05-03
- Known ransomware campaign use
- Unknown
Exploit context
What the vulnerability is about.
Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace.
Source
Where this page information comes from.
Original source
Original source links
Open the public records and source datasets used for this page.
