CVE-2016-0785
published 2016-04-12CVE-2016-0785: Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation.
PriorityP357high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
8.81%
94.6th percentile
Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | struts | >= 2.0.0 < 2.3.29 | 2.3.29 |
| apache | struts | >= 2.0.0 < 2.3.20.3 | 2.3.20.3 |
| apache | struts | 2.3.21 – 2.3.24.1 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect forced double OGNL evaluation by looking for '%{}' sequences in HTTP request tag attribute values targeting Apache Struts 2.x endpoints ↗
- →Monitor for double evaluation of attributes' values assigned to certain tags in Apache Struts — input containing OGNL expressions that get evaluated a second time during tag rendering is the attack pattern ↗
- →Reference the vendor advisory S2-029 for payload patterns and affected tag list associated with this vulnerability ↗
- ·The fix for CVE-2016-0785 (patched in 2.3.28) was incomplete; CVE-2016-4461 covers the same attack vector and requires upgrading to Apache Struts 2.3.29 or later for full remediation ↗
- ·struts2-core JARs were bundled in source packages of Red Hat Fuse Service Works 6.0.0 and Single Sign On 7.3.0+ via a Google Guice import; customers who built artifacts from those source packages may have introduced vulnerable JARs into their environments ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
ghsa8.8HIGH
osv8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Struts forced double OGNL evaluation
osv·2022-05-14·CVSS 8.8
CVE-2016-4461 [HIGH] Apache Struts forced double OGNL evaluation
Apache Struts forced double OGNL evaluation
Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-0785.
OSV
Apache Struts RCE Vulnerability
osv·2022-05-14
CVE-2016-0785 [HIGH] Apache Struts RCE Vulnerability
Apache Struts RCE Vulnerability
Apache Struts 2.x before 2.3.20.3, 2.3.24.3, and 2.3.28 allows remote attackers to execute arbitrary code via a `%{}` sequence in a tag attribute, aka forced double OGNL evaluation.
GHSA
Apache Struts RCE Vulnerability
ghsa·2022-05-14
CVE-2016-0785 [HIGH] CWE-20 Apache Struts RCE Vulnerability
Apache Struts RCE Vulnerability
Apache Struts 2.x before 2.3.20.3, 2.3.24.3, and 2.3.28 allows remote attackers to execute arbitrary code via a `%{}` sequence in a tag attribute, aka forced double OGNL evaluation.
GHSA
Apache Struts forced double OGNL evaluation
ghsa·2022-05-14·CVSS 8.8
CVE-2016-4461 [HIGH] CWE-20 Apache Struts forced double OGNL evaluation
Apache Struts forced double OGNL evaluation
Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-0785.
Red Hat
struts2: forced double OGNL evaluation on raw input in tag attributes
vendor_redhat·2016-04-13·CVSS 8.8
CVE-2016-0785 [HIGH] CWE-20 struts2: forced double OGNL evaluation on raw input in tag attributes
struts2: forced double OGNL evaluation on raw input in tag attributes
Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation.
Statement: A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in any Red Hat provided final products, and does not cause any vulnerability in the product, struts2-core jars have been included in some products' source code packages. The inclusion was part of an import of the Google Guice repository, which includes struts2-core. Customers that build artefacts from our sourc
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-0785 struts2: forced double OGNL evaluation on raw input in tag attributes
bugzilla·2016-04-13·CVSS 8.8
CVE-2016-0785 [HIGH] CVE-2016-0785 struts2: forced double OGNL evaluation on raw input in tag attributes
CVE-2016-0785 struts2: forced double OGNL evaluation on raw input in tag attributes
The Apache Struts frameworks when forced, performs double evaluation of attributes' values assigned to certain tags so it is possible to pass in a value that will be evaluated again when a tag's attributes will be rendered.
External references:
http://struts.apache.org/docs/s2-029.html
Discussion:
Statement:
A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in any Red Hat provided final products, and does not cause any vulnerability in the product, struts2-core jars have been included in some products' sourc
arXiv
SeqTrans: Automatic Vulnerability Fix via Sequence to Sequence Learning
arxiv_fulltext·2022-03-22
SeqTrans: Automatic Vulnerability Fix via Sequence to Sequence Learning
SeqTrans: Automatic Vulnerability Fix via Sequence to Sequence Learning
Jianlei Chi,
Yu Qu,
Ting Liu, Member, IEEE,
Qinghua Zheng, Member, IEEE,
Heng Yin, Member, IEEE
J. Chi, T. Liu and Q. Zheng are with the Ministry of Education Key Lab For Intelligent Networks and Network Security (MOEKLINNS), School of Computer Science and Technology, Xian Jiaotong University, Xian 710049, China.
Email: [email protected], tliu, [email protected].
Y. Qu and H. Yin are with the Department of Computer Science and Engineering, UC Riverside, California, USA.
\ : [email protected], [email protected]
Journal of \ Class Files, Vol. 14, No. 8, May 2021
Shell et al.: Bare Advanced Demo of IEEEtran.cls for IEEE Computer Society Journals
## Abstract
Software vulnerabilities are now reported unprecedented
2016-04-12
Published