VYPR
Critical severityCISA KEVNVD Advisory· Published Dec 11, 2020· Updated Oct 21, 2025

CVE-2020-17530

CVE-2020-17530

Description

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.struts:struts2-coreMaven
>= 2.0.0, < 2.5.262.5.26

Affected products

1
  • Apache Software Foundation/Apache Strutsv5
    Range: Struts 2.0.0 - Struts 2.5.25

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

15

News mentions

0

No linked articles in our index yet.