UNKNOWNKNOWN EXPLOITED
CVE-2017-9805
Apache Struts Deserialization of Untrusted Data Vulnerability
Summary
Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.
References
Includes data from the CISA Known Exploited Vulnerabilities catalog.
CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.