Security advisories

Apache Struts REST Plugin Vulnerability (CVE-2017-9805)

February 26, 2019 | 1 MIN READ

Speak With A Security Expert Now

TALK TO AN EXPERT

Researchers have found a critical remote code execution vulnerability in Apache Struts REST Plugin. Clients using Apache Struts versions 2.1.2 to 2.3.33, or 2.5 to 2.5.12 are highly encouraged to patch immediately.

Recommended Action

eSentire highly recommends upgrading to either Struts 2.3.34 or Struts 2.5.13 to mitigate this threat.

Additional Information

This vulnerability is addressed by ensuring your Struts version has been updated to version 2.3.34 or 2.5.13.

Public exploits have been reported, therefore patching vulnerable systems should be treated as a priority. Apache has released a security bulletin with further details on this vulnerability, as well as solutions and workarounds. Read the full bulletin here:

S2-052 - Apache Struts 2 Documentation - Apache Software Foundation

View Most Recent Advisories