Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 – Struts 2.5.25.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17530
Reference (s):
- https://cwiki.apache.org/confluence/display/WW/S2-061
- URL: https://cwiki.apache.org/confluence/display/WW/S2-061
- https://security.netapp.com/advisory/ntap-20210115-0005/
- URL: https://security.netapp.com/advisory/ntap-20210115-0005/
- JVN:JVN#43969166

