CVE-2017-9791: Apache Struts 1 Improper Input Validation Vulnerability
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
Other sources
The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
— CISA
The Struts 1 plugin used with Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
— GitHub
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9791?
CVE-2017-9791 has been rated as critical due to its potential for remote code execution.
How do I fix CVE-2017-9791?
To fix CVE-2017-9791, upgrade to Apache Struts version 2.3.32 or later.
What versions are affected by CVE-2017-9791?
CVE-2017-9791 affects Apache Struts versions 2.1.x and 2.3.x up to 2.3.31.
What type of vulnerability is CVE-2017-9791?
CVE-2017-9791 is a remote code execution vulnerability in the Struts 1 plugin.
Can CVE-2017-9791 be exploited remotely?
Yes, CVE-2017-9791 can be exploited remotely if the vulnerable version is exposed.