Vulnerability library
Security checkMay 13, 2024

Apache Struts 2 REST plugin XStream RCE S2-052

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

High severityRCEStrutsInjection

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

Apache Struts 2, specifically the REST Plugin, is susceptible to a Remote Code Execution (RCE) vulnerability identified as S2-052. This vulnerability arises due to the use of a XStreamHandler with an instance of XStream for deserialization without adequate type filtering. Attackers can exploit this flaw by submitting malicious XML payloads, leading to the execution of arbitrary code on the server.

Recommendation

To mitigate this vulnerability, it is recommended to upgrade to Apache Struts version 2.5.13, 2.3.34, or newer versions.

References

Could your website be exposed too?

SmartScanner can check your website for Apache Struts 2 REST plugin XStream RCE S2-052 and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated May 13, 2024