{"cvss":0.0,"datePublished":"2022-02-10","dateUpdated":"2022-02-10","description":"The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.","dueDate":"2022-08-10","id":"CVE-2017-9791","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Unknown","notes":"https://nvd.nist.gov/vuln/detail/CVE-2017-9791","product":"Struts 1","requiredAction":"Apply updates per vendor instructions.","severity":"HIGH","source":"cisa_known_exploited","title":"Apache Struts 1 Improper Input Validation Vulnerability","vendor":"Apache"}