CVE-2021-31805

Apache Struts Remote Code Execution Vulnerability S2-062 (CVE-2021-31805) Alert

April 14, 2022

Overview On April 13, 2022, NSFOCUS CERT detected that Struts officially issued a security notice and fixed a remote code execution vulnerability S2-062 (CVE-2021-31805). This vulnerability is not fully repaired for S2-061. When developers use the %{…} syntax to force OGNL parsing, there are still some special TAG attributes that can be parsed twice; attackers […]

Search

Subscribe to the NSFOCUS Blog