CVE-2017-12611 is an expression-injection vulnerability affecting Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1. Applications that use expression literals or force expression evaluation in FreeMarker tags, rather than using string literals, can expose attacker-controlled request values to expression evaluation, enabling remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository provides a proof-of-concept (POC) exploit for CVE-2017-12611, a remote code execution vulnerability in Apache Struts 2. The repository contains three files: a .gitattributes file, a markdown file with the OGNL payload (payload.md), and a detailed readme (read_me.md) with setup and exploitation instructions. The exploit leverages an OGNL injection payload that, when submitted to a vulnerable Struts 2 endpoint (e.g., http://<your-ip>:8080/hello.action), executes arbitrary system commands on the server. The readme guides the user to set up a vulnerable environment using Docker Compose, submit the payload via Burp Suite, and obtain a shell by transforming intercepted requests into curl commands. The exploit demonstrates RCE by running the 'id' command but can be adapted for other commands. No detection scripts or fake elements are present; the repository is a functional POC for the specified vulnerability.
This repository contains a Python script (exploit.py) and a README.md file. The script exploits the Apache Struts 2 S2-053 vulnerability (CVE-2017-12611), which allows for remote code execution via crafted OGNL expressions in HTTP GET parameters. The exploit.py script takes three arguments: a target URL, a parameter name, and a system command to execute. It constructs a malicious OGNL payload that is injected into the specified parameter and sends a GET request to the target. If successful, the output of the executed command is returned in the HTTP response. The README provides usage instructions, an example, and references to further information. The exploit is operational and allows arbitrary command execution on vulnerable Struts 2 servers.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The Apache Struts Freemarker tag vulnerability.
A remote code execution vulnerability in Apache Struts, allowing attackers to execute arbitrary code via crafted OGNL expressions.
An N-day vulnerability exploited by UTG-Q-015's scanning infrastructure against publicly accessible government and enterprise web servers. The reference does not describe its technical mechanism or identify the vulnerable software.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.