Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2017-5638

Quick assessment

Affected
Apache Software Foundation Apache Struts
Exploitation
Confirmed exploitation in the wild; remediate immediately
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache Struts是美国阿帕奇(Apache)软件基金会的一个开源项目,是一套用于创建企业级Java Web应用的开源MVC框架,主要提供两个版本框架产品,Struts 1和Struts 2。 Apache Struts 2 2.3.32之前的2 2.3.x版本和2.5.10.1之前的2.5.x版本中的Jakarta Multipart解析器存在安全漏洞,该漏洞源于程序没有正确处理文件上传。远程攻击者可借助带有#cmd=字符串的特制Content-Type HTTP头利用该漏洞执行任意命令。

AI Predicted 9.8 Difficulty: Easy KEV · Ransomware EPSS 100.00% · P100

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2017-5638

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Apache Struts 2 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apache Struts是美国阿帕奇(Apache)软件基金会的一个开源项目,是一套用于创建企业级Java Web应用的开源MVC框架,主要提供两个版本框架产品,Struts 1和Struts 2。 Apache Struts 2 2.3.32之前的2 2.3.x版本和2.5.10.1之前的2.5.x版本中的Jakarta Multipart解析器存在安全漏洞,该漏洞源于程序没有正确处理文件上传。远程攻击者可借助带有#cmd=字符串的特制Content-Type HTTP头利用该漏洞执行任意命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Struts 2.3.x before 2.3.32 -

II. Public POCs for CVE-2017-5638

# POC Description Source Link Shenlong Link
1 Struts2 S2-045(CVE-2017-5638)Vulnerability environment - http://www.mottoin.com/97954.html https://github.com/PolarisLab/S2-045 POC Details
2 Struts2 S2-045(CVE-2017-5638)Exp with GUI https://github.com/Flyteas/Struts2-045-Exp POC Details
3 None https://github.com/bongbongco/cve-2017-5638 POC Details
4 S2-045 漏洞 POC-TOOLS CVE-2017-5638 https://github.com/jas502n/S2-045-EXP-POC-TOOLS POC Details
5 Telegram Bot to manage botnets created with struts vulnerability(CVE-2017-5638) https://github.com/mthbernardes/strutszeiro POC Details
6 Example PoC Code for CVE-2017-5638 | Apache Struts Exploit https://github.com/xsscx/cve-2017-5638 POC Details
7 Demo Application and Exploit https://github.com/immunio/apache-struts2-CVE-2017-5638 POC Details
8 This is Valve for Tomcat7 to block Struts 2 Remote Code Execution vulnerability (CVE-2017-5638) https://github.com/Masahiro-Yamada/OgnlContentTypeRejectorValve POC Details
9 Tweaking original PoC (https://github.com/rapid7/metasploit-framework/issues/8064) to work on self-signed certificates https://github.com/aljazceru/CVE-2017-5638-Apache-Struts2 POC Details
10 test struts2 vulnerability CVE-2017-5638 in Mac OS X https://github.com/sjitech/test_struts2_vulnerability_CVE-2017-5638 POC Details
11 None https://github.com/jrrombaldo/CVE-2017-5638 POC Details
12 CVE: 2017-5638 in different formats https://github.com/random-robbie/CVE-2017-5638 POC Details
13 detection for Apache Struts recon and compromise https://github.com/initconf/CVE-2017-5638_struts POC Details
14 An exploit for Apache Struts CVE-2017-5638 https://github.com/mazen160/struts-pwn POC Details
15 These are just some script which you can use to detect and exploit the Apache Struts Vulnerability (CVE-2017-5638) https://github.com/ret2jazzy/Struts-Apache-ExploitPack POC Details
16 A php based exploiter for CVE-2017-5638. https://github.com/lolwaleet/ExpStruts POC Details
17 Example PHP Exploiter for CVE-2017-5638 https://github.com/oktavianto/CVE-2017-5638-Apache-Struts2 POC Details
18 cve-2017-5638 Vulnerable site sample https://github.com/jrrdev/cve-2017-5638 POC Details
19 Struts2 RCE CVE-2017-5638 non-intrusive check shell script https://github.com/opt9/Strutshock POC Details
20 Apache Struts (CVE-2017-5638) Shell https://github.com/falcon-lnhg/StrutsShell POC Details
21 None https://github.com/bhagdave/CVE-2017-5638 POC Details
22 st2-046-poc CVE-2017-5638 https://github.com/jas502n/st2-046-poc POC Details
23 S2-046|S2-045: Struts 2 Remote Code Execution vulnerability(CVE-2017-5638) https://github.com/KarzsGHR/S2-046_S2-045_POC POC Details
24 CVE-2017-5638 https://github.com/gsfish/S2-Reaper POC Details
25 None https://github.com/mcassano/cve-2017-5638 POC Details
26 Struts2 RCE CVE-2017-5638 CLI shell https://github.com/opt9/Strutscli POC Details
27 Strutsy - Mass exploitation of Apache Struts (CVE-2017-5638) vulnerability https://github.com/tahmed11/strutsy POC Details
28 Apache Struts 2.0 RCE vulnerability - Allows an attacker to inject OS commands into a web application through the content-type header https://github.com/payatu/CVE-2017-5638 POC Details
29 CVE-2017-5638 https://github.com/Aasron/Struts2-045-Exp POC Details
30 An exploit for CVE-2017-5638 Remote Code Execution (RCE) Vulnerability in Apache Struts 2 https://github.com/SpiderMate/Stutsfi POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-5638

请登录查看更多情报信息。

Vendor Advisories for CVE-2017-5638 (6)

Exploits & Public PoCs for CVE-2017-5638 (3)

Proof of Concept for CVE-2017-5638 (1)

Mailing List Discussions for CVE-2017-5638 (2)

Security Blog Posts for CVE-2017-5638 (3)

News Coverage for CVE-2017-5638 (1)

Other References for CVE-2017-5638 (14)

IV. Related Vulnerabilities

V. Comments for CVE-2017-5638

No comments yet


Leave a comment