CVE-2017-5638: Apache Struts Remote Code Execution Vulnerability
Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.
Other sources
Apache Struts versions prior to 2.3.32 and 2.5.10.1 contain incorrect exception handling and error-message generation during file-upload attempts using the Jakarta Multipart parser, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.struts:struts2-coreto a version that resolves this vulnerability.Fixed in 2.5.10.1 - Upgrade
Upgrade
maven/org.apache.struts:struts2-coreto a version that resolves this vulnerability.Fixed in 2.3.32 - Upgrade
Upgrade
Apache Struts 2to a version that resolves this vulnerability.Fixed in 2.3.32 - Upgrade
Upgrade
Apache Struts 2to a version that resolves this vulnerability.Fixed in 2.5.10.1
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5638?
CVE-2017-5638 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2017-5638?
To remediate CVE-2017-5638, upgrade to Apache Struts version 2.3.32 or 2.5.10.1 or later.
What versions of Apache Struts are affected by CVE-2017-5638?
CVE-2017-5638 affects Apache Struts versions prior to 2.3.32 and 2.5.10.1.
What type of threat does CVE-2017-5638 pose?
CVE-2017-5638 poses a threat of remote code execution through malicious file uploads.
Are there any specific software products that utilize the vulnerable Struts versions in CVE-2017-5638?
Various products like IBM Storwize and HP Server Automation may utilize affected versions of Apache Struts related to CVE-2017-5638.