S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2018-11776 Scanner

CVE-2018-11776 scanner - Remote Code Execution (RCE) vulnerability in Apache Software Foundation Struts

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.1k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2018-11776
8.1
CVSShigh
Exploitable remotely over the internet · no authentication required.

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Apache Strutsby Apache Software Foundation
2.3 to 2.3.34
Updated Aug 21, 2026View on NVD →
Detail

Apache Struts is a widely-used open-source framework for developing enterprise-level Java web applications. It provides a set of APIs for building complex web applications, while also facilitating the MVC (Model View Controller) architecture. Many organizations prefer Apache Struts as it helps in reducing application development time, improving application security, and providing a highly flexible system for developers. With the increased adoption of Apache Struts in various industries, it is essential to ensure the software is secure.

Recently, a serious vulnerability, CVE-2018-11776, was detected in Apache Struts 2.3 to 2.3.34 and 2.5 to 2.5.16. This flaw affects systems wherein 'alwaysSelectFullNamespace' is enabled or set to 'true,' which happens either by the user or by a plugin such as the Convention Plugin. The vulnerability is in the results used without namespace and is related to its upper package without a namespace or a wildcard namespace. It is also present when using URL tags without a value and action set and is related to its upper package without a namespace or a wildcard namespace.

Exploiting the CVE-2018-11776 vulnerability can cause severe consequences as it allows an attacker to execute arbitrary code remotely. When exploited, attackers can gain complete control of the affected system and obtain sensitive information, such as passwords, credit card details, and other confidential data. The vulnerability can be exploited by sending a specially crafted HTTP request to the affected server, which allows attackers to execute arbitrary code remotely.

In conclusion, ensuring that your digital assets are secure is of utmost importance in today's digital age. s4e.io is a platform that offers advanced security features to help its clients stay ahead of potential threats and vulnerabilities. With the help of s4e.io, clients can easily and quickly learn about vulnerabilities in their digital assets and take necessary precautions to keep their assets secure. By coupling s4e.io with the suggested precautions outlined above, users can rest assured their digital assets are safe and sound.

 

REFERENCES

Solution Advice

To mitigate the risks associated with the CVE-2018-11776 vulnerability, here are some precautions that can be taken: 

  • Disable or set the 'alwaysSelectFullNamespace' to 'false.'
  • Ensure that all packages used in the application have a namespace defined.
  • Upgrade to the latest version of Apache Struts, which includes a patch for the CVE-2018-11776 vulnerability.
  • Use firewalls and intrusion detection/prevention systems to monitor network traffic and detect and prevent malicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-11776 scanner - Remote Code Execution (RCE) vulnerability in Apache Software Foundation Struts  | S4E