Web Hack List

Collected research

Struts 2 OGNL Double Evaluation RCE

Security Research Laboratory : Struts 2 Remote ...

A Coverity write-up of the Struts 2 wildcard-mapping RCE: an action name of the form ${...} or %{...} reaches StrutsResultSupport.conditionalParse and is evaluated a second time as OGNL, so a URL alone reaches Runtime.exec. JavaSnoop tracing pins the sink, and the same double evaluation is found in HttpHeaderResult and DefaultUrlHelper. Fixed in 2.3.14.2.

Record

Document
Security Research Laboratory : Struts 2 Remote ...
Published by
communities.coverity.com
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of communities.coverity.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .