← KEV catalog
CISA known exploited vulnerability

CVE-2020-17530

Apache Struts Remote Code Execution Vulnerability

SOURCE FACT

Apache · Struts

Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2020-17530

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?