CVE-2020-17530Apache Struts Remote Code Execution Vulnerability

PUBLISHEDvulnerability record
2021-11-03 · last modified June 21, 2025

Metadata

CVE ID:
CVE-2020-17530
Project:
Apache
Product:
Struts
Date Added:
2021-11-03
Due Date:
2022-05-03
Last Updated:
June 21, 2025

Vulnerability Name

Apache Struts Remote Code Execution Vulnerability

Description

Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution.

Known To Be Used in Ransomware Campaigns?

Ransomware Status:
Unknown

Action

Apply updates per vendor instructions.

Additional Notes

Related Weaknesses