CVE-2017-5638
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.
CISA KEV
- Vendor
- Apache
- Product
- Struts
- Due date
- 2022-05-03
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://nvd.nist.gov/vuln/detail/CVE-2017-5638
Exploits
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | org.apache.struts:struts2-core | >=2.3.0,<2.3.32 | 2.3.32 |
| Maven | org.apache.struts:struts2-core | >=2.5.0,<2.5.10.1 | 2.5.10.1 |
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-5638
- https://github.com/rapid7/metasploit-framework/issues/8064
- https://github.com/apache/struts/commit/b06dd50af2a3319dd896bf5c2f4972d2b772cf2b
- https://github.com/apache/struts/commit/352306493971e7d5a756d61780d57a76eb1f519a
- https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c@%3Cannounce.apache.org%3E
- https://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922%40%3Cannounce.apache.org%3E
- https://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922@%3Cannounce.apache.org%3E
- https://nmap.org/nsedoc/scripts/http-vuln-cve2017-5638.html
- https://packetstormsecurity.com/files/141494/S2-45-poc.py.txt
- https://security.netapp.com/advisory/ntap-20170310-0001
- https://struts.apache.org/docs/s2-045.html
- https://struts.apache.org/docs/s2-046.html
- https://support.lenovo.com/us/en/product_security/len-14200
- https://twitter.com/theog150/status/841146956135124993
- https://web.archive.org/web/20170311203630/http://www.securityfocus.com/bid/96729
- https://web.archive.org/web/20170921030226/http://www.securitytracker.com/id/1037973
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-5638
- https://www.exploit-db.com/exploits/41614
- https://www.imperva.com/blog/2017/03/cve-2017-5638-new-remote-code-execution-rce-vulnerability-in-apache-struts-2
- https://www.kb.cert.org/vuls/id/834067
- https://www.symantec.com/security-center/network-protection-security-advisories/SA145
- https://arstechnica.com/security/2017/03/critical-vulnerability-under-massive-attack-imperils-high-impact-sites
- https://cwiki.apache.org/confluence/display/WW/S2-045
- https://cwiki.apache.org/confluence/display/WW/S2-046
- https://exploit-db.com/exploits/41570
Verify integrity in audit chain (admin only). AS-IS.