cbcvebase.
CVE-2018-11776
published 2018-08-22

CVE-2018-11776: Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a…

PriorityP195high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
99.99%
100.0th percentile
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.

Affected

12 ranges
VendorProductVersion rangeFixed in
apachestruts>= 2.0.4 < 2.3.352.3.35
apachestruts>= 2.5.0 < 2.5.172.5.17
apache_software_foundationapache_struts
apache_software_foundationapache_struts
netappactive_iq_unified_manager>= 7.3
netappactive_iq_unified_manager>= 9.5
oraclecommunications_policy_management< 12.5.012.5.0
oracleenterprise_manager_base_platform
oracleenterprise_manager_base_platform
oraclemysql_enterprise_monitor<= 3.4.9.4237
oraclemysql_enterprise_monitor4.0.0 – 4.0.6.5281
oraclemysql_enterprise_monitor8.0.0 – 8.0.2.8191

Detection & IOCsextracted from sources · hover to see the quote

ip95.161.225.94
ip167.114.171.27
urlhttps://github.com/cnrig/cnrig/releases/download/v0.1.5-release/cnrig-0.1.5-linux-x86_64
urlhttps://bitbucket.org/c646/zz/downloads/upcheck.sh
urlhttps://bitbucket.org/c646/zz/downloads/386
urlhttps://bitbucket.org/c646/zz/downloads/arm
urlhttps://bitbucket.org/c646/zz/downloads/mips
domainus-east.cryptonight-hub.miningpoolhub.com
port20580
filenamexrig
filenameupcheck.sh
  • Scan for vulnerable Struts by sending crafted payloads to .action, .go, .do, .jsp and .xhtml files under common web directories and checking for command execution evidence.
  • For authenticated Linux/Unix detection, execute 'ps -ef', look for the Tomcat process, and locate the struts2-core-x.jar file to confirm vulnerable Struts versions.
  • For unauthenticated remote detection, use a plugin that attempts to exploit the vulnerability and sends an ICMP echo (ping) request from the remote host back to the scanner host to verify successful exploitation.
  • Monitor for outbound connections to cryptomining pool us-east.cryptonight-hub.miningpoolhub.com on TCP port 20580 as a post-exploitation indicator.
  • ·The vulnerability only exists when 'alwaysSelectFullNamespace' is true AND results/url tags lack a namespace or use a wildcard namespace — it does NOT exist in a default Struts configuration.
  • ·The alwaysSelectFullNamespace flag is automatically set to true when the Struts Convention plugin is in use, broadening the attack surface beyond explicit configuration.
  • ·Authenticated version-based plugins (e.g., Tenable Plugin 112036) cannot determine if a workaround is in place and must be run with 'Show potential false alarms' accuracy setting.
  • ·The remote unauthenticated Tenable plugin (112064) will not work from Tenable.io scanner pools due to the nature of the blind RCE verification mechanism; on-prem scanners are required.
  • ·The mining pool domain IOC (us-east.cryptonight-hub.miningpoolhub.com) is indicative of cryptomining activity broadly and not exclusively tied to CVE-2018-11776 exploitation.

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck8.1HIGH
cisa8.1HIGH
vendor_oracle8.1HIGH
vendor_redhat8.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.