PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Misconfiguration·Updated Jan 3, 2024

CVE-2010-1870 Scanner

CVE-2010-1870 scanner - Remote Code Execution (RCE) vulnerability in Struts

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2010-1870
5.0
CVSS

The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly other products, uses a permissive whitelist, which allows remote attackers to modify server-side context objects and bypass the "#" protection mechanism in ParameterInterceptors via the (1) #context, (2) #_memberAccess, (3) #root, (4) #this, (5) #_typeResolver, (6) #_classResolver, (7) #_traceEvaluations, (8) #_lastEvaluation, (9) #_keepLastEvaluation, and possibly other OGNL context variables, a different vulnerability than CVE-2008-6504.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Struts is an open-source web application framework for Java. It is designed to develop elegant, extensible, and maintainable enterprise web applications. Struts is widely used by organizations to build custom web applications since it provides a consistent and well-documented framework. The framework supports a model-view-controller (MVC) architecture which separates the application’s data, user interface, and control logic. By using Struts, developers can easily build web applications that expand over time, incorporate robust security features, and promote reusability.

CVE-2010-1870 is a vulnerability that affects Struts 2.0.0 to 2.1.8.1. The vulnerability is related to an extensive expression evaluation capability called Object-Graph Navigation Language (OGNL). The whitelist in OGNL is permissive, which allows attackers to modify server-side context objects and bypass the "#" protection mechanism in ParameterInterceptors using OGNL context variables such as #context, #_memberAccess, #root, #this, #_typeResolver, #_classResolver, #_traceEvaluations, #_lastEvaluation, #_keepLastEvaluation, and potentially others. Attackers who exploit this vulnerability can inject malicious code, execute unauthorized commands, or access sensitive system files.

When an attacker successfully exploits CVE-2010-1870, they can gain unauthorized access to sensitive data or manipulate the system's behavior. The attacker can obtain confidential information such as login credentials, personally identifiable information, and financial data. The attacker can also execute unauthorized system commands leading to the destruction of the system, alter the system's configuration, or install malware. The breach can also affect the confidentiality, integrity, and availability of the web application and its data.

Looking to protect your digital assets from vulnerabilities? s4e.io has got you covered. With pro features on their platform, you can easily and quickly gain insights into the vulnerabilities that may be present in your digital assets. By subscribing to their advanced security services, you can rest assured that your digital assets are protected against the latest security threats. Get started today and protect your digital assets with s4e.io.

 

REFERENCES

Solution Advice

The following precautions can be taken to protect against CVE-2010-1870:

  • Upgrade to the latest version of Struts
  • Implement appropriate web application firewalls
  • Regularly scan web applications for vulnerabilities
  • Limit the use of OGNL expressions
  • Use input sanitization and validation techniques

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2010-1870 scanner - Remote Code Execution (RCE) vulnerability in Struts | S4E