CISA Known Exploited Vulnerability

CVE-2020-17530

Apache · Struts

Apache Struts Remote Code Execution Vulnerability

Date added
BOD 22-01 due date
CWE CWE-917
Ransomware Unknown

CISA description

Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution.

Required action

Apply updates per vendor instructions.