Public Date:
1489478: CVE-2017-12611 struts: RCE attack when using an unintentional expression in Freemarker tag instead of string literals
It was found that Freemarker in Struts would permit using read-only properties in value assignment of tag expressions. An attacker could use this to execute arbitrary code.

Find out more about CVE-2017-12611 from the MITRE CVE dictionary dictionary and NIST NVD.


This issue did not affect any of the Red Hat products as they did not include the Apache Struts 2 package. Furthermore, Red Hat Enterprise Linux versions 6 and 7 do not ship any Struts packages.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 8.1
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector Network
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity Impact High
Availability Impact High

Affected Packages State

Platform Package State
Red Hat Satellite 5 struts Not affected
Red Hat JBoss Operations Network 3 struts Not affected
Red Hat JBoss Fuse Service Works 6 struts Not affected
Red Hat JBoss Data Virtualization 6 struts Not affected
Red Hat Enterprise Linux 5 struts Not affected

External References

Last Modified