The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
Published: 2017-03-14
A remote code execution vulnerability (CVE-2017-5638) in the Jakarta Multipart Parser in certain versions of the Apache Struts framework can enable a remote attacker to run arbitrary commands on the web server. Since its initial disclosure, this vulnerability has received significant attention, and is reportedly exploited in the wild. Public exploits are also available for this vulnerability.
https://www.kb.cert.org/vuls/id/834067
https://support.lenovo.com/us/en/product_security/len-14200
https://security.netapp.com/advisory/ntap-20170310-0001/
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03723en_us
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03749en_us
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
http://www.eweek.com/security/apache-struts-vulnerability-under-attack.html
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-002.txt
https://www.theregister.com/2024/12/12/apache_struts_2_vuln/
https://securelist.com/vulnerability-exploit-report-q2-2024/113455/
https://securityaffairs.com/155935/malware/nkabuse-abuses-nkn-technology.html
https://www.secureworks.com/research/gold-melody-profile-of-an-initial-access-broker?&web_view=true
https://www.tenable.com/cyber-exposure/2020-threat-landscape-retrospective
https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-133a
https://www.tenable.com/blog/from-bugs-to-breaches-25-significant-cves-as-mitre-cve-turns-25
https://www.tenable.com/blog/new-apache-struts-vulnerability-could-allow-for-remote-code-execution
https://github.com/Sudo-Zaid/cve-poc-writeups
https://github.com/RenatoAntunovic/cve-metasploit-skeniranje
https://github.com/lr-elaina520/cve-analysis
https://github.com/chengbochuan3/CVE-Apache-Ecosystem
https://github.com/Athology0000/cve-lab
https://github.com/HaakimSec/zero2shell-50
https://github.com/sudichai/cve-destroyer
https://github.com/enjoylife96962930-a11y/bug-bounty-series-2026
https://github.com/kokunas/fraud-cve
https://github.com/amitvakk/dark-overlord-threat-intelligence-analysis
https://github.com/kokunas/java-app-cve
https://github.com/Hector-Abarca/realrisk-checks
https://github.com/manahylkhan/cveradar
https://github.com/Lanexus/cve-scanner
https://github.com/heyjerrybecker/seevie-pri
https://github.com/allannjuguna/Exploit-Development
https://github.com/Dungsocool/CVE-2017-5638
https://github.com/flags-alt/abyss-c2
https://github.com/Majaktech/apache-struts-cve-2017-5638-project
https://github.com/wyqsgy/vulnark
https://github.com/guilhermeferreira24/healthcare-cybersecurity-analysis
https://github.com/Kouf320/docker-lab-cve-2017-5638-cve-2021-41773
https://github.com/Kouf320/attacker-lab-cve-2017-5638-cve-2021-41773-paper
https://github.com/AIPEACS/SC3010-Computer-Security
https://github.com/AIPEAC/SC3010-Computer-Security
https://github.com/ericrlessa/java-exploitable-quiz
https://github.com/lizuyi-6/aetherguard-security-dataset
https://github.com/Deloney-code/AI-Powered-Red-Team-Automation
https://github.com/JerryT-cell/Container-Security-Risk-Assessment-Pipeline-using-LLMs
https://github.com/soufiane-benchahyd/vulhub-struts2
https://github.com/ndouglas-cloudsmith/ExploitPwned
https://github.com/CVE-ORG/CVE-ORG
https://github.com/Arthurfert/SecLLM-Gen
https://github.com/0xBentz1/cve-context-knowledge-base
https://github.com/ACharaf06/CVE-2017-5638-Attack-and-Defense
https://github.com/0wn2886/CVE-Web
https://github.com/scthornton/securecode-v2
https://github.com/kaylertee/Computer-Security-Equifax-2017
https://github.com/abdullah89255/Bug-bounty-pentesting-and-CVE-trends
https://github.com/root6790/security-research
https://github.com/joidiego/Detection-struts-cve-2017-5638-detector
https://github.com/cyberleelawat/LeelawatX-CVE-Hunter
https://github.com/haxerr9/CVE-2017-5638
https://github.com/Nithylesh/web-application-firewall-
https://github.com/FredBrave/CVE-2017-5638-ApacheStruts2.3.5
https://github.com/mritunjay-k/CVE-2017-5638
https://github.com/mfdev-solution/Exploit-CVE-2017-5638
https://github.com/testpilot031/vulnerability_struts-2.3.31
https://github.com/jptr218/struts_hack
https://github.com/sonatype-workshops/struts2-rce
https://github.com/ludy-dev/XworkStruts-RCE
https://github.com/pasannirmana/Aspire
https://github.com/colorblindpentester/CVE-2017-5638
https://github.com/advisories/GHSA-j77q-2qqg-6989
https://github.com/andypitcher/check_struts
https://github.com/Iletee/struts2-rce
https://github.com/ggolawski/struts-rce
https://github.com/pr0x1ma-byte/cybersecurity-struts2
https://github.com/donaldashdown/Common-Vulnerability-and-Exploit
https://github.com/c002/Apache-Struts
https://github.com/evolvesecurity/vuln-struts2-vm
https://github.com/invisiblethreat/strutser
https://github.com/mike-williams/Struts2Vuln
https://github.com/eeehit/CVE-2017-5638
https://github.com/riyazwalikar/struts-rce-cve-2017-5638
https://github.com/jpacora/Struts2Shell
https://github.com/SpiderMate/Stutsfi
https://github.com/Aasron/Struts2-045-Exp
https://github.com/tahmed11/strutsy
https://github.com/opt9/Strutscli
https://github.com/gsfish/S2-Reaper
https://github.com/KarzsGHR/S2-046_S2-045_POC
https://github.com/jas502n/st2-046-poc
https://github.com/falcon-lnhg/StrutsShell
https://github.com/opt9/Strutshock
https://github.com/lolwaleet/ExpStruts
https://github.com/ret2jazzy/Struts-Apache-ExploitPack
https://github.com/mazen160/struts-pwn
https://github.com/sjitech/test_struts2_vulnerability_CVE-2017-5638
https://github.com/Masahiro-Yamada/OgnlContentTypeRejectorValve
https://github.com/mthbernardes/strutszeiro
https://github.com/jas502n/S2-045-EXP-POC-TOOLS
https://github.com/Flyteas/Struts2-045-Exp
https://github.com/PolarisLab/S2-045
https://www.symantec.com/security-center/network-protection-security-advisories/SA145
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-5638
https://twitter.com/theog150/status/841146956135124993
https://struts.apache.org/docs/s2-046.html
https://struts.apache.org/docs/s2-045.html
https://packetstormsecurity.com/files/141494/S2-45-poc.py.txt
https://nmap.org/nsedoc/scripts/http-vuln-cve2017-5638.html
https://isc.sans.edu/diary/22169
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03733en_us
https://github.com/rapid7/metasploit-framework/issues/8064
https://cwiki.apache.org/confluence/display/WW/S2-046
https://cwiki.apache.org/confluence/display/WW/S2-045
http://www.securitytracker.com/id/1037973
http://www.securityfocus.com/bid/96729
http://blog.talosintelligence.com/2017/03/apache-0-day-exploited.html