claytonvantol.us
SESSION: secure TLS: 1.3 PID: 1337

clayton@site:~/news$ cat cve-2018-11776-apache-struts.log

CVE-2018-11776 — Apache Struts Remote Code Execution Vulnerability

2021-11-03 • CISA Known Exploited Vulnerability


[event] Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace.

> AFFECTED SOFTWARE

Field Value
Vendor Apache
Product Struts
CWE CWE-20
CVE ID CVE-2018-11776
Date Added 2021-11-03
Due Date 2022-05-03
Ransomware Campaign Unknown

> MITIGATION

Apply updates per vendor instructions.

Due Date: 2022-05-03

> REFERENCES


← back to terminal

UPTIME: 1337d v2.0.1 privacy LAST LOGIN: 2026-05-30 20:36:15 UTC