CVE-2020-17530—Apache Struts Remote Code Execution Vulnerability
PUBLISHEDvulnerability record
2021-11-03 · last modified June 21, 2025
Metadata
Vulnerability Name
Apache Struts Remote Code Execution Vulnerability
Description
Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution.
Known To Be Used in Ransomware Campaigns?
Action
Apply updates per vendor instructions.