Skip to main content

CVE detail

CVE-2018-11776

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.

CVSS 8.1 · HighBuzz score 68.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 68.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 13.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
22 evidence mentions in the snapshot
Diversity score
13.0
4 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
22 source links · newest first
  • Organizations in the financial and insurance sectors were the most targeted by threat actors in 2020, continuing a trend that was first observed roughly five years ago, IBM Security reports.

    newswww.securityweek.comApr 2, 2021, 12:42 PM
  • Have you already updated your Apache Struts 2 to version 2.5.22, released in November 2019? You might want to, and quickly, as information about a potential RCE vulnerability (CVE-2019-0230) and PoC exploits for it have been published. About the vulnerability (CVE-2019-0230) “CVE-2019-0230 is a forced double Object-Graph Navigation Language (OGNL) evaluation vulnerability that occurs when Struts tries to perform an evaluation of raw user input inside of tag attributes. An attacker could exploit this vulnerability … More →

    newswww.helpnetsecurity.comAug 17, 2020, 10:03 AM
  • Oracle released the first critical patch advisory for 2019 that addresses a total of 284 vulnerabilities, 33 of them are rated “critical”. Let’s give a close look at some of the vulnerabilities fixed by this patch advisory. The advisory fixed the CVE-2016-1000031 flaw, a remote code execution (RCE) bug in the Apache Commons FileUpload, disclosed in November […]

    newssecurityaffairs.comJan 18, 2019, 1:15 PM
  • Apache Struts developers are urging users to update a file upload library due to the existence of two vulnerabilities that can be exploited for remote code execution and denial-of-service (DoS) attacks.

    newswww.securityweek.comNov 6, 2018, 2:21 PM
  • Oracle’s October 2018 Critical Patch Update (CPU) was rolled out on Tuesday with 301 security fixes, bringing the total of patches released this year to 1,119.

    newswww.securityweek.comOct 17, 2018, 9:54 AM
  • There’s some good and some bad news for the Patch Tuesday forecast this month. The good news is a number of vendors have just released last week, clearing the slate for what might be a fairly Microsoft-focused Patch Tuesday. The bad news is there are a number of third-party updates already released this week that you will want to evaluate alongside the Microsoft release, if you have not already prioritized them for deployment. There is … More →

    newswww.helpnetsecurity.comSep 10, 2018, 5:45 AM
  • Cisco has plugged a heap of security holes – three of which are critical – in a variety of its products. The critical flaws The flaws deemed critical are: A DoS and RCE vulnerability (CVE-2018-0423) in the web-based management interface of three series of Cisco wireless VPN routers: RV110W, RV130W, and RV215W. Unfortunately, it has only been fixed in the RV130W series. An Apache Struts RCE vulnerability (CVE-2018-11776) that affects twenty different Cisco products. This … More →

    newswww.helpnetsecurity.comSep 6, 2018, 8:21 PM
  • Cisco has released thirty security patch advisory to address a total of 32 security vulnerabilities in its products, including three critical flaws. Cisco released thirty security patch advisory to address a total of 32 security vulnerabilities in its products. The good news is that the tech giant is not aware of any exploitation of the addressed vulnerabilities […]

    newssecurityaffairs.comSep 6, 2018, 12:38 PM
  • Oracle informed customers over the weekend that some of the company’s products are affected by a critical Apache Struts 2 vulnerability that has been exploited in the wild.

    newswww.securityweek.comSep 4, 2018, 10:22 AM
  • Here’s an overview of some of last week’s most interesting news and articles: 0patch releases micropatch for Windows Task Scheduler zero-day Acros Security, the company behind 0patch, has released a micropatch for the flaw that can be applied to fully updated 64bit Windows 10 version 1803 and 64bit Windows Server 2016. Air Canada confirms mobile app data breach, passport numbers were accessed Air Canada has suffered a data breach and is forcing a password reset … More →

    newswww.helpnetsecurity.comSep 3, 2018, 12:30 PM
  • A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Let me inform you that my new book, “Digging in the Deep Web” is online with a special deal 20% discount Kindle Edition Paper Copy Once again thank you! · Personal details of 37,000 Eir customers exposed […]

    newssecurityaffairs.comSep 2, 2018, 11:10 AM
  • According to the threat intelligence firm Volexity, the CVE-2018-11776 vulnerability is already being abused in malicious attacks in the wild. Just yesterday I wrote about the availability online of the exploit code for the recently discovered Critical remote code execution vulnerability CVE-2018-11776 in Apache Struts 2. The PoC code was published on GitHub and experts were warning of […]

    newssecurityaffairs.comAug 28, 2018, 4:07 PM
  • A Critical remote code execution vulnerability in Apache Struts 2 that was patched last week is already being abused in malicious attacks, threat intelligence firm Volexity warns.

    newswww.securityweek.comAug 28, 2018, 2:07 PM
  • The Apache Software Foundation revealed last week the existence of a critical Apache Struts flaw (CVE-2018-11776) similar to the one exploited in the Equifax breach and urged organizations and developers to upgrade their installations to versions 2.3.35 or 2.5.17. The vulnerability was flagged by Semmle security researcher Man Yue Mo and the company joined ASF’s entreaties for speedy mitigation. “Previous disclosures of similarly critical vulnerabilities have resulted in exploits being published within a day, putting … More →

    newswww.helpnetsecurity.comAug 27, 2018, 3:26 PM
  • The Exploit code for the recently discovered Critical remote code execution vulnerability CVE-2018-11776 in Apache Struts 2 was published on GitHub, experts fear massive attacks. The CVE-2018-11776 vulnerability affects Struts 2.3 through 2.3.34, Struts 2.5 through 2.5.16, and potentially unsupported versions of the popular Java framework. “Possible Remote Code Execution when using results with no namespace and […]

    newssecurityaffairs.comAug 27, 2018, 3:12 PM
  • Exploit code for a Critical remote code execution vulnerability in Apache Struts 2 was published on GitHub within days after the bug was addressed last week.

    newswww.securityweek.comAug 27, 2018, 9:52 AM
  • Here’s an overview of some of last week’s most interesting news and articles: The importance of career pathing in the cybersecurity industry A major issue facing our industry right now is a significant shortage of talented, skilled cybersecurity professionals. Whether that’s due to lack of interest or a fundamental misunderstanding of how to gain a foothold in information security, it’s a problem that industry professionals around the globe are working to address. Critical Apache Struts … More →

    newswww.helpnetsecurity.comAug 26, 2018, 7:21 PM
  • A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Let me inform you that my new book, “Digging in the Deep Web” is online with a special deal 20% discount Kindle Edition Paper Copy Once again thank you! · Chinas Belt and Road project (BRI) is […]

    newssecurityaffairs.comAug 26, 2018, 12:36 PM
  • Unit 42 Threat Brief with info & protections on Critical Apache Struts Vulnerability CVE-2018-11776.

    vendorunit42.paloaltonetworks.comAug 24, 2018, 8:36 PM
  • A critical remote code execution vulnerability (CVE-2018-11776) in Apache Struts, the popular open source framework for developing Java-based web apps, could allow remote attackers to run malicious code on the affected servers. The vulnerability was discovered and reported by Semmle security researcher Man Yue Mo, and the company urges organizations and developers who use Struts to upgrade their Struts components immediately. “Previous disclosures of similarly critical vulnerabilities have resulted in exploits being published within a … More →

    newswww.helpnetsecurity.comAug 23, 2018, 2:17 PM
  • Maintainers of the Apache Struts 2 open source development framework has released security updates to address a critical remote code execution vulnerability. Security updates released this week for the Apache Struts 2 open source development framework addressed a critical RCE tracked as CVE-2018-11776. The vulnerability affects Struts versions from 2.3 through 2.3.34, Struts 2.5 through 2.5.16, and […]

    newssecurityaffairs.comAug 22, 2018, 5:23 PM
  • Updates released on Wednesday for the Apache Struts 2 open source development framework address a critical vulnerability that can be exploited for remote code execution. The flaw, tracked as CVE-2018-11776 , affects Struts 2.3 through 2.3.34, Struts 2.5 through 2.5.16, and possibly unsupported versions of the framework.

    newswww.securityweek.comAug 22, 2018, 4:10 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence