The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.
PoC: s2-062
远程代码执行S2-062 CVE-2021-31805验证POC
PoC: CVE-2021-31805
S2-062 (CVE-2021-31805) / S2-061 / S2-059 RCE
PoC: S2-062
Apache Struts2 S2-062远程代码执行漏洞(CVE-2021-31805) 支持批量扫描漏洞及漏洞利用
PoC: Struts2_S2-062_CVE-2021-31805
Apache Struts2 S2-062远程代码执行漏洞(CVE-2021-31805) | 反弹Shell
PoC: CVE-2021-31805
PoC for CVE-2021-31805 (Apache Struts2)
PoC: CVE-2021-31805-POC
Apache Struts2 S2-062(CVE-2021-31805)远程代码执行批量检测(无利用)
PoC: CVE-2021-31805
Vulnerable environment of CVE-2021-31805 (S2-062) for testing
PoC: CVE-2021-31805
S2-061/S2-062 Struts2 远程命令执行漏洞 POC&EXP
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free