CVE-2017-12611: Input Validation
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.
Other sources
In Apache Struts 2.0.1 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.
— GitHub
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12611?
CVE-2017-12611 has a critical severity due to the potential for remote code execution vulnerabilities.
How do I fix CVE-2017-12611?
To fix CVE-2017-12611, upgrade to Apache Struts versions 2.5.11 or 2.3.34 or higher.
What versions are affected by CVE-2017-12611?
CVE-2017-12611 affects Apache Struts versions 2.0.0 to 2.3.33 and 2.5 to 2.5.10.1.
Can CVE-2017-12611 be exploited remotely?
Yes, CVE-2017-12611 can be exploited remotely if the application is misconfigured and accepts untrusted input.
Is there a patch available for CVE-2017-12611?
Yes, patches are available in the form of updated versions of Apache Struts, specifically 2.5.11 and 2.3.34.