Vulnerability CVE-2018-11776


Published: 2018-08-22

Description:
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.

See advisories in our WLB2 database:
Topic
Author
Date
High
Apache Struts 2.3 to 2.3.34 and 2.5 to 2.5.16 Remote Code Execution PoC
Man Yue Mo
23.08.2018
High
Apache Struts CVE-2018-11776 Exploit (python)
Mazin Ahmed
29.08.2018
High
Apache Struts 2 Namespace Redirect OGNL Injection
wvu
08.09.2018

Type:

CWE-20

(Improper Input Validation)

Vendor: Apache
Product: Struts 
Version:
2.5.9
2.5.8
2.5.7
2.5.6
2.5.5
2.5.4
2.5.3
2.5.2
2.5.16
2.5.15
2.5.14.1
2.5.14
2.5.13
2.5.11
2.5.10
2.5.1
2.3.9
2.3.8
2.3.7
2.3.6
2.3.5
2.3.4.1
2.3.4
2.3.33
2.3.32
2.3.31
2.3.30
2.3.3
2.3.29
2.3.28.1
2.3.28
2.3.27
2.3.26
2.3.25
2.3.24.3
2.3.24.2
2.3.24
2.3.23
2.3.22
2.3.21
2.3.20.3
2.3.20.2
2.3.20.1
2.3.20
2.3.19
2.3.17
2.3.16.3
2.3.16.2
2.3.16.1
2.3.16
2.3.15.3
2.3.15.2
2.3.15.1
2.3.15
2.3.14.3
2.3.14.2
2.3.14.1
2.3.14
2.3.13
2.3.12
2.3.11
2.3.10
2.3.1.2
2.3.1.1
2.3.1

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.3/10
10/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete

 References:
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-005.txt
http://www.oracle.com/technetwork/security-advisory/alert-cve-2018-11776-5072787.html
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
http://www.securityfocus.com/bid/105125
http://www.securitytracker.com/id/1041547
http://www.securitytracker.com/id/1041888
https://cwiki.apache.org/confluence/display/WW/S2-057
https://github.com/hook-s3c/CVE-2018-11776-Python-PoC
https://lgtm.com/blog/apache_struts_CVE-2018-11776
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0012
https://security.netapp.com/advisory/ntap-20180822-0001/
https://security.netapp.com/advisory/ntap-20181018-0002/
https://www.exploit-db.com/exploits/45260/
https://www.exploit-db.com/exploits/45262/
https://www.exploit-db.com/exploits/45367/
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html

Related CVE
CVE-2019-10072
The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) cl...
CVE-2017-15694
When an Apache Geode server versions 1.0.0 to 1.8.0 is operating in secure mode, a user with write permissions for specific data regions can modify internal cluster metadata. A malicious user could modify this data in a way that affects the operation...
CVE-2019-10085
In Apache Allura prior to 1.11.0, a vulnerability exists for stored XSS on the user dropdown selector when creating or editing tickets. The XSS executes when a user engages with that dropdown on that page.
CVE-2019-0197
A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection cou...
CVE-2019-0196
A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handling could be made to access freed memory in string comparison when determining the method of a request and thus process the request ...
CVE-2019-0220
A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for duplicates in regular expressions...
CVE-2018-11801
SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on a m_center data related table.
CVE-2018-11800
SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts related table.

Copyright 2019, cxsecurity.com

 

Back to Top