cve-2020-17530
HIGH CVSS 8.1 csaf_redhat
Description
This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.
Timeline
- Published
- 2020-12-08 00:00 UTC
- Last Modified
- 2026-08-05
CVSS Details
CVSS details not available.
Affected Products
No product information available.
Weaknesses (CWE)
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"document": {
"aggregate_severity": {
"namespace": "https://access.redhat.com/security/updates/classification/",
"text": "Important"
},
"category": "csaf_vex",
"csaf_version": "2.0",
"distribution": {
"text": "Copyright © Red Hat, Inc. All rights reserved.",
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "en",
"notes": [
{
"category": "legal_disclaimer",
"text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
"title": "Terms of Use"
}
],
"publisher": {
"category": "vendor",
"contact_details": "https://access.redhat.com/security/team/contact/",
"issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
"name": "Red Hat Product Security",
"namespace": "https://www.redhat.com"
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-17530.json"
}
],
"title": "struts2: using forced OGNL evaluation on untrusted user input can lead to a RCE and security degradation",
"tracking": {
"current_release_date": "2026-08-05T03:52:05+00:00",
"generator": {
"date": "2026-08-05T03:52:05+00:00",
"engine": {
"name": "Red Hat SDEngine",
"version": "5.3.8"
}
},
"id": "CVE-2020-17530",
"initial_release_date": "2020-12-08T00:00:00+00:00",
"revision_history": [
{
"date": "2020-12-08T00:00:00+00:00",
"number": "1",
"summary": "Initial version"
},
{
"date": "2026-08-04T12:02:01+00:00",
"number": "2",
"summary": "Current version"
},
{
"date": "2026-08-05T03:52:05+00:00",
"number": "3",
"summary": "Last generated version"
}
],
"status": "final",
"version": "3"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_name",
"name": "Red Hat JBoss Enterprise Application Platform 6",
"product": {
"name": "Red Hat JBoss Enterprise Application Platform 6",
"product_id": "red_hat_jboss_enterprise_application_platform_6",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:6"
}
}
}
],
"category": "product_family",
"name": "Red Hat JBoss Enterprise Application Platform 6"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat JBoss Fuse 6",
"product": {
"name": "Red Hat JBoss Fuse 6",
"product_id": "red_hat_jboss_fuse_6",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:jboss_fuse:6"
}
}
}
],
"category": "product_family",
"name": "Red Hat JBoss Fuse 6"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat JBoss Fuse Service Works 6",
"product": {
"name": "Red Hat JBoss Fuse Service Works 6",
"product_id": "red_hat_jboss_fuse_service_works_6",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:jboss_fuse_service_works:6"
}
}
}
],
"category": "product_family",
"name": "Red Hat JBoss Fuse Service Works 6"
},
{
"branches": [
{
"category": "product_name",
"name": "Red Hat JBoss Operations Network 3",
"product": {
"name": "Red Hat JBoss Operations Network 3",
"product_id": "red_hat_jboss_operations_network_3",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:jboss_operations_network:3"
}
}
}
],
"category": "product_family",
"name": "Red Hat JBoss Operations Network 3"
},
{
"category": "product_version",
"name": "struts",
"product": {
"name": "struts",
"product_id": "struts"
}
},
{
"category": "product_version",
"name": "struts-core",
"product": {
"name": "struts-core",
"product_id": "struts-core",
"product_identification_helper": {
"purl": "pkg:maven/org.apache.struts/struts-core"
}
}
}
],
"category": "vendor",
"name": "Red Hat"
}
],
"relationships": [
{
"category": "default_component_of",
"full_product_name": {
"name": "struts as a component of Red Hat JBoss Enterprise Application Platform 6",
"product_id": "red_hat_jboss_enterprise_application_platform_6:struts"
},
"product_reference": "struts",
"relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_6"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "struts-core as a component of Red Hat JBoss Fuse 6",
"product_id": "red_hat_jboss_fuse_6:struts-core"
},
"product_reference": "struts-core",
"relates_to_product_reference": "red_hat_jboss_fuse_6"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "struts as a component of Red Hat JBoss Fuse Service Works 6",
"product_id": "red_hat_jboss_fuse_service_works_6:struts"
},
"product_reference": "struts",
"relates_to_product_reference": "red_hat_jboss_fuse_service_works_6"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "struts as a component of Red Hat JBoss Operations Network 3",
"product_id": "red_hat_jboss_operations_network_3:struts"
},
"product_reference": "struts",
"relates_to_product_reference": "red_hat_jboss_operations_network_3"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2020-17530",
"cwe": {
"id": "CWE-20",
"name": "Improper Input Validation"
},
"discovery_date": "2020-12-08T00:00:00+00:00",
"flags": [
{
"label": "vulnerable_code_not_present",
"product_ids": [
"red_hat_jboss_enterprise_application_platform_6:struts",
"red_hat_jboss_fuse_6:struts-core",
"red_hat_jboss_fuse_service_works_6:struts",
"red_hat_jboss_operations_network_3:struts"
]
}
],
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "1905645"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in the Apache Struts frameworks. When forced, some of the tag's attributes perform a double evaluation if a developer applies forced OGNL evaluation by using the %{...} syntax. Using a forced OGNL evaluation on untrusted user input allows an attacker to perform remote code execution and security degradation. The highest threat from this vulnerability is to data confidentiality, integrity as well as system availability.",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "struts2: using forced OGNL evaluation on untrusted user input can lead to a RCE and security degradation",
"title": "Vulnerability summary"
},
{
"category": "other",
"text": "Apache Struts2 is not compiled, shipped, used, or enabled in Red Hat products. As such, any CVE against Apache Struts2 does not impact currently supported Red Hat products.\n\nThis statement was last revised on 1 Sept 2020.\n\nPrevious statement example: https://bugzilla.redhat.com/show_bug.cgi?id=1469265",
"title": "Statement"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"known_not_affected": [
"red_hat_jboss_enterprise_application_platform_6:struts",
"red_hat_jboss_fuse_6:struts-core",
"red_hat_jboss_fuse_service_works_6:struts",
"red_hat_jboss_operations_network_3:struts"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2020-17530"
},
{
"category": "external",
"summary": "RHBZ#1905645",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1905645"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2020-17530",
"url": "https://www.cve.org/CVERecord?id=CVE-2020-17530"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2020-17530",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-17530"
},
{
"category": "external",
"summary": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
}
],
"release_date": "2020-12-08T00:00:00+00:00",
"scores": [
{
"cvss_v3": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"red_hat_jboss_enterprise_application_platform_6:struts",
"red_hat_jboss_fuse_6:struts-core",
"red_hat_jboss_fuse_service_works_6:struts",
"red_hat_jboss_operations_network_3:struts"
]
}
],
"threats": [
{
"category": "exploit_status",
"date": "2021-11-03T00:00:00+00:00",
"details": "CISA: https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
},
{
"category": "impact",
"details": "Important",
"product_ids": [
"red_hat_jboss_enterprise_application_platform_6:struts",
"red_hat_jboss_fuse_6:struts-core",
"red_hat_jboss_fuse_service_works_6:struts",
"red_hat_jboss_operations_network_3:struts"
]
}
],
"title": "struts2: using forced OGNL evaluation on untrusted user input can lead to a RCE and security degradation"
}
]
}
Enrichment data
Aggregated bundle (all enrichments)