What You Need to Know About the Apache Struts Vulnerability by Gilad David Maayan

Feb 15, 2020

Apache Struts is a popular open-source framework, used to create web apps. Due to its popularity, Apache Struts attracts a large number of attackers. The framework has a considerable number of vulnerabilities, one of which was exploited during the notorious Equifax breach, way back in 2017. The framework has since been updated. However, even though these vulnerabilities have been made known and patched in the latest versions, many users have failed to upgrade. 

What Is the Apache Struts Vulnerability?

Apache Struts is an open-source Model-View-Controller (MVC) framework used to create web applications in Java. The Apache Struts vulnerability is a flaw that enables attackers to remotely execute code. 

There are actually multiple vulnerabilities that have been discovered in the last few years which allow this sort of attack in Struts. Of these vulnerabilities, CVE-2017-5638 is the specific vulnerability used in the Equifax credit bureau breach in 2017.

  • CVE-2017-5638
  • CVE-2017-9791
  • CVE-2017-9805 
  • CVE-2018-11776

The most recent vulnerability (CVE-2018-11776), enables attackers to exploit a user input validation flaw. Specifically, attackers can insert Object-Graph Navigation Language (OGNL) expressions in Uniform Resource Identifier (URI) queries. These are sent through insufficiently validated HTTP requests. 


Hakin9 TEAM
Hakin9 is a monthly magazine dedicated to hacking and cybersecurity. In every edition, we try to focus on different approaches to show various techniques - defensive and offensive. This knowledge will help you understand how most popular attacks are performed and how to protect your data from them. Our tutorials, case studies and online courses will prepare you for the upcoming, potential threats in the cyber security world. We collaborate with many individuals and universities and public institutions, but also with companies such as Xento Systems, CATO Networks, EY, CIPHER Intelligence LAB, redBorder, TSG, and others.
Notify of

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Oldest Most Voted
Inline Feedbacks
View all comments
© HAKIN9 MEDIA SP. Z O.O. SP. K. 2023