Red Hat Bugzilla – Bug 1489478
CVE-2017-12611 struts: RCE attack when using an unintentional expression in Freemarker tag instead of string literals
Last modified: 2018-02-12 06:27:05 EST
When using expression literals or forcing expression in Freemarker tags (see example below) and using request values, it can lead to RCE attack. <@s.hidden name="redirectUri" value=redirectUri /> <@s.hidden name="redirectUri" value="${redirectUri}" /> In both cases a writable property is used in the value attribute and in both cases this is threatened as an expression by Freemarker. Affected versions: Struts 2.0.1 - Struts 2.3.33, Struts 2.5 - Struts 2.5.10 External References: https://struts.apache.org/docs/s2-053.html
Statement: This issue did not affect any of the Red Hat products as they did not include the Apache Struts 2 package. Furthermore, Red Hat Enterprise Linux versions 6 and 7 do not ship any Struts packages.