CRITICAL

CVE-2021-31805

CVSS v3

9.8

CRITICAL

EPSS Score

94.0%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.

Technical details

Published
4/12/2022

Frequently asked questions

What is CVE-2021-31805?

The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.

Is CVE-2021-31805 actively exploited?

Active exploitation of CVE-2021-31805 has not been confirmed. The EPSS score is 94.0%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-31805?

CVE-2021-31805 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2021-31805 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.