S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-0230 Scanner

CVE-2019-0230 scanner - Remote Code Execution (RCE) vulnerability in Apache Software Foundation Struts

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
4.3k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-0230
9.8
CVSS

Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Apache Strutsby n/a
Apache Struts 2.0.0 to 2.5.20
Updated Aug 21, 2026View on NVD →
Detail

Apache Struts is an open-source framework that is used to develop Java web applications. It follows the Model-View-Controller (MVC) architectural pattern and provides a set of reusable components and tools that simplify the development process. The framework is widely popular among Java developers due to its flexibility and ease of use.

CVE-2019-0230 is a vulnerability that was recently detected in Apache Struts. This security flaw exists in versions 2.0.0 to 2.5.20 and can be exploited to execute malicious code remotely. The root cause of the vulnerability lies in how the framework handles user input in tag attributes, allowing for double evaluation of the Object-Graph Navigation Language (OGNL) expression.

If exploited, this vulnerability can lead to various security issues, such as unauthorized access to sensitive data, remote code execution, and system hijacking. Attackers can take advantage of the vulnerability to execute their own code on the server. This can result in the attacker gaining full control of the system, stealing confidential information, modifying data, or even installing malware.

s4e.io is a platform that provides comprehensive security solutions for organizations of all sizes. With its Pro Features, users can quickly and easily identify vulnerabilities in their digital assets and take informed actions to protect against them. By leveraging the platform's advanced features, businesses can ensure the security and integrity of their web applications and safeguard against the latest threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is crucial to follow the best practices for securing web applications. Some of the key precautions that can be taken include: - Keep the Apache Struts framework up to date with the latest security patches

  • Monitor the application for any suspicious activity
  • Use trusted input validation mechanisms to prevent malicious input from reaching the server
  • Implement strict access control measures to limit the privileges of users and roles
  • Deploy a robust web application firewall to block known attacks

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-0230 scanner - Remote Code Execution (RCE) vulnerability in Apache Software Foundation Struts  | S4E