CVE-2021-31805 in Apache and Oracle Products
Published on April 12, 2022
Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.
Weakness Type
What is an EL Injection Vulnerability?
The software constructs all or part of an expression language (EL) statement in a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.
CVE-2021-31805 has been classified to as an EL Injection vulnerability or weakness.
Products Associated with CVE-2021-31805
stack.watch emails you whenever new vulnerabilities are published in Apache Struts or Oracle. Just hit a watch button to start following.
Affected Versions
Apache Software Foundation Apache Struts Version 2.0.0 to 2.5.29 is affected by CVE-2021-31805Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.