{"id":"GHSA-gg9m-fj3v-r58c","summary":"REST Plugin in Apache Struts uses an XStreamHandler with an instance of XStream for deserialization without any type filtering","details":"The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.","aliases":["CVE-2017-9805"],"modified":"2025-10-22T18:00:48.862300Z","published":"2018-10-16T19:37:56Z","database_specific":{"github_reviewed_at":"2020-06-16T21:37:16Z","nvd_published_at":"2017-09-15T19:29:00Z","cwe_ids":["CWE-502"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-9805"},{"type":"WEB","url":"https://github.com/apache/struts/commit/19494718865f2fb7da5ea363de3822f87fbda26"},{"type":"WEB","url":"https://github.com/apache/struts/commit/6dd6e5cfb7b5e020abffe7e8091bd63fe97c10a"},{"type":"WEB","url":"https://blogs.apache.org/foundation/entry/apache-struts-statement-on-equifax"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1488482"},{"type":"WEB","url":"https://cwiki.apache.org/confluence/display/WW/S2-052"},{"type":"PACKAGE","url":"https://github.com/apache/struts"},{"type":"WEB","url":"https://lgtm.com/blog/apache_struts_CVE-2017-9805"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20170907-0001"},{"type":"WEB","url":"https://struts.apache.org/docs/s2-052.html"},{"type":"WEB","url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170907-struts2"},{"type":"WEB","url":"https://web.archive.org/web/20170909031344/http://www.securityfocus.com/bid/100609"},{"type":"WEB","url":"https://web.archive.org/web/20170922053119/http://www.securitytracker.com/id/1039263"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-9805"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/42627"},{"type":"WEB","url":"https://www.kb.cert.org/vuls/id/112992"},{"type":"WEB","url":"http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/100609"},{"type":"WEB","url":"http://www.securitytracker.com/id/1039263"}],"affected":[{"package":{"name":"org.apache.struts:struts2-rest-plugin","ecosystem":"Maven","purl":"pkg:maven/org.apache.struts/struts2-rest-plugin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.1.1"},{"fixed":"2.3.34"}]}],"versions":["2.1.2","2.1.6","2.1.8","2.1.8.1","2.2.1","2.2.1.1","2.2.3","2.2.3.1","2.3.1","2.3.1.1","2.3.1.2","2.3.12","2.3.14","2.3.14.1","2.3.14.2","2.3.14.3","2.3.15","2.3.15.1","2.3.15.2","2.3.15.3","2.3.16","2.3.16.1","2.3.16.2","2.3.16.3","2.3.20","2.3.20.1","2.3.20.3","2.3.24","2.3.24.1","2.3.24.3","2.3.28","2.3.28.1","2.3.29","2.3.3","2.3.30","2.3.31","2.3.32","2.3.33","2.3.4","2.3.4.1","2.3.7","2.3.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-gg9m-fj3v-r58c/GHSA-gg9m-fj3v-r58c.json"}},{"package":{"name":"org.apache.struts:struts2-rest-plugin","ecosystem":"Maven","purl":"pkg:maven/org.apache.struts/struts2-rest-plugin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.5.0"},{"fixed":"2.5.13"}]}],"versions":["2.5","2.5.1","2.5.10","2.5.10.1","2.5.12","2.5.2","2.5.5","2.5.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-gg9m-fj3v-r58c/GHSA-gg9m-fj3v-r58c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H"}]}