Skip to main content

Apache Releases Security Updates

Scheduled updates for Apache Struts 2

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Scheduled updates for Apache Struts 2


Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

The Apache Software Foundation has released a security update to address a vulnerability known as CVE-2021-31805 in Apache Struts 2.

In December 2020, the Apache Software Foundation released fix S2-061, which was meant to fully remediate vulnerability CVE-2020-17530. The fix was not complete, however, and so the remaining vulnerability is CVE-2021-31805. Both vulnerabilities concern forced Object-Graph Navigation Language (OGNL) evaluation under certain conditions leading to possible remote code execution.

A remote attacker could exploit this vulnerability to take control of an affected system.


Remediation advice

Affected organisations are encouraged to review Apache Security Bulletin S2-062 and apply the necessary update or workaround.



Last edited: 14 April 2022 12:36 pm