CVE-2018-11776Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.
CWE-20 · Improper input validation
Exploited in the wild
Confirmed real-world exploitation.
CVSS E:A
| Index | Artifact | Stars | First seen |
|---|---|---|---|
| GitHub PoC | An exploit for Apache Struts CVE-2018-11776 | 303 | 2018-08-25 |
| Nuclei | Apache Struts2 S2-057 - Remote Code Execution | ||
| Exploit-DB | Apache Struts 2 - Namespace Redirect OGNL Injection (Metasploit) | 2018-09-10 | |
| GitHub PoC | Working Python test and PoC for CVE-2018-11776, includes Docker lab | 123 | 2018-08-24 |
| Exploit-DB | Apache Struts 2 - Namespace Redirect OGNL Injection (Metasploit) | 2018-09-10 | |
| GitHub PoC | This tool takes advantage of CVE-2018-11776 and Shodan to perform mass exploitation of verified and vulnerable Apache Struts servers. | 56 | 2018-08-29 |
| Exploit-DB | Apache Struts 2.3 < 2.3.34 / 2.5 < 2.5.16 - Remote Code Execution (1) | 2018-08-26 | |
| GitHub PoC | Proof of Concept for CVE-2018-11776 | 21 | 2018-08-27 |
| Exploit-DB | Apache Struts 2.3 < 2.3.34 / 2.5 < 2.5.16 - Remote Code Execution (2) | 2018-08-25 | |
| GitHub PoC | Critical Remote Code Execution Vulnerability (CVE-2018-11776) Found in Apache Struts. | 17 | 2019-10-10 |
A Waratek agent blocks this today.
Applicable rule: Manual classification assigned status: MITIGATED-BY-SECURE-RULE
| Decided by | manual classification : Manual classification of this CVE in the legacy dataset |
|---|---|
| Finding | Manual classification assigned status: MITIGATED-BY-SECURE-RULE |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
3 metrics
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 3.1 | 8.1 | HIGH | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
NVD | Primary | published |
| CVSS 3.1 | 8.1 | HIGH | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
CISA-ADP | Secondary | |
| CVSS 2.0 | 9.3 | no band published | AV:N/AC:M/Au:N/C:C/I:C/A:C |
NVD | Primary |
| Advisory | Type | Quarter | Products Oracle named in risk matrix |
|---|---|---|---|
| Oracle Critical Patch Update July 2020 ↗ | CPU | 2020-Q3 | Oracle Enterprise Manager / Reporting Framework (Apache Struts 2) (13.3.0.0, 13.4.0.0) |
| Oracle Critical Patch Update January 2019 ↗ | CPU | 2019-Q1 | Oracle Communications Applications / Security (Apache Struts 2) (prior to 12.5) |
| Oracle Critical Patch Update October 2018 ↗ | CPU | 2018-Q4 | Oracle MySQL / Monitoring: General (Apache Struts 2) (3.4.9.4237 and prior, 4.0.6.5281 and prior, 8.0.2.8191 and prior) |
| Family | Component | Oracle's version cell (verbatim) | Indexed as |
|---|---|---|---|
| Oracle Communications Applications | Security (Apache Struts 2) | prior to 12.5 | |
| Oracle Enterprise Manager | Reporting Framework (Apache Struts 2) | 13.3.0.0, 13.4.0.0 | 13.3.0.0 · 13.4.0.0 |
| Oracle MySQL | Monitoring: General (Apache Struts 2) | 3.4.9.4237 and prior, 4.0.6.5281 and prior, 8.0.2.8191 and prior |
| Package Coordinate | Introduced | Fixed | Last affected |
|---|---|---|---|
org.apache.struts:struts2-core |
2.0.4 | 2.3.35 |
unbounded |
org.apache.struts:struts2-core |
2.5 | 2.5.17 |
unbounded |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| nvd | apache | struts | generic | ≥ 2.0.4 and < 2.3.35 · ≥ 2.5.0 and < 2.5.17 |
| nvd | netapp | active iq unified manager | generic | ≥ 7.3 · ≥ 9.5 |
| nvd | netapp | oncommand insight | generic | any version |
| nvd | netapp | oncommand workflow automation | generic | any version |
| nvd | netapp | snapcenter | generic | any version |
| nvd | oracle | communications policy management | generic | < 12.5.0 |
| nvd | oracle | enterprise manager base platform | generic | 13.3.0.0 · 13.4.0.0 |
| nvd | oracle | mysql enterprise monitor | generic | ≤ 3.4.9.4237 · ≥ 4.0.0 and ≤ 4.0.6.5281 · ≥ 8.0.0 and ≤ 8.0.2.8191 |
| osv | org.apache.struts | struts2-core | generic | ≥ 2.0.4 and < 2.3.35 · ≥ 2.5 and < 2.5.17 |
A reviewer manually classified this CVE. The retained record includes the labels and products below, but not the reviewer's reasoning.
## Manual Classification Context **Labels:** HTTP, SECURITY (APACHE STRUTS 2), REPORTING FRAMEWORK (APACHE STRUTS 2), NO AUTH REMOTE EXPLOIT, MONITORING: GENERAL (APACHE STRUTS 2) **Products:** APACHE STRUTS 2
| Published | 2018-08-22 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-06-17 | NVD's own last-modified date for this record. |