The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
https://www.kb.cert.org/vuls/id/112992
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170907-struts2
https://security.netapp.com/advisory/ntap-20170907-0001/
https://bugzilla.redhat.com/show_bug.cgi?id=1488482
http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html
https://thehackernews.com/2025/11/from-log4j-to-iis-chinas-hackers-turn.html
https://www.security.com/threat-intelligence/china-apt-us-policy
https://www.darkreading.com/threat-intelligence/earth-lamia-exploits-sql-rce-bugs-asia
https://thehackernews.com/2025/05/china-linked-hackers-exploit-sap-and.html
https://www.securityweek.com/chinese-hacking-group-earth-lamia-targets-multiple-industries/
https://www.trendmicro.com/en_us/research/25/e/earth-lamia.html
https://github.com/chengbochuan3/CVE-Apache-Ecosystem
https://github.com/FarizDevloper/CVE-2017-2024
https://github.com/ucsb-seclab/CVEX-records
https://github.com/0xd3vil/CVE-2017-9805-Exploit
https://github.com/jongmartinez/-CVE-2017-9805-
https://github.com/UbuntuStrike/CVE-2017-9805-Apache-Struts-Fuzz-N-Sploit
https://github.com/UbuntuStrike/struts_rest_rce_fuzz-CVE-2017-9805-
https://github.com/advisories/GHSA-gg9m-fj3v-r58c
https://github.com/chrisjd20/cve-2017-9805.py
https://github.com/0x00-0x00/-CVE-2017-9805
https://github.com/Lone-Ranger/apache-struts-pwn_CVE-2017-9805
https://github.com/mazen160/struts-pwn_CVE-2017-9805
https://github.com/luc10/struts-rce-cve-2017-9805
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-9805
https://struts.apache.org/docs/s2-052.html
https://lgtm.com/blog/apache_struts_CVE-2017-9805
https://cwiki.apache.org/confluence/display/WW/S2-052
https://blogs.apache.org/foundation/entry/apache-struts-statement-on-equifax