Apache Releases Security Updates
Scheduled updates for Apache Struts 2
Summary
Scheduled updates for Apache Struts 2
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
The Apache Software Foundation has released a security update to address a vulnerability known as CVE-2021-31805 in Apache Struts 2.
In December 2020, the Apache Software Foundation released fix S2-061, which was meant to fully remediate vulnerability CVE-2020-17530. The fix was not complete, however, and so the remaining vulnerability is CVE-2021-31805. Both vulnerabilities concern forced Object-Graph Navigation Language (OGNL) evaluation under certain conditions leading to possible remote code execution.
A remote attacker could exploit this vulnerability to take control of an affected system.
Remediation advice
Affected organisations are encouraged to review Apache Security Bulletin S2-062 and apply the necessary update or workaround.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 14 April 2022 12:36 pm