cve-2020-17530

HIGH CVSS 8.1 csaf_redhat
Description

This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

Timeline
Published
2020-12-08 00:00 UTC
Last Modified
2026-08-05
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-17530.json"
      }
    ],
    "title": "struts2: using forced OGNL evaluation on untrusted user input can lead to a RCE and security degradation",
    "tracking": {
      "current_release_date": "2026-08-05T03:52:05+00:00",
      "generator": {
        "date": "2026-08-05T03:52:05+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.8"
        }
      },
      "id": "CVE-2020-17530",
      "initial_release_date": "2020-12-08T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2020-12-08T00:00:00+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-04T12:02:01+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-08-05T03:52:05+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss Enterprise Application Platform 6",
                "product": {
                  "name": "Red Hat JBoss Enterprise Application Platform 6",
                  "product_id": "red_hat_jboss_enterprise_application_platform_6",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:6"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Enterprise Application Platform 6"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss Fuse 6",
                "product": {
                  "name": "Red Hat JBoss Fuse 6",
                  "product_id": "red_hat_jboss_fuse_6",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_fuse:6"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Fuse 6"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss Fuse Service Works 6",
                "product": {
                  "name": "Red Hat JBoss Fuse Service Works 6",
                  "product_id": "red_hat_jboss_fuse_service_works_6",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_fuse_service_works:6"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Fuse Service Works 6"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss Operations Network 3",
                "product": {
                  "name": "Red Hat JBoss Operations Network 3",
                  "product_id": "red_hat_jboss_operations_network_3",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_operations_network:3"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Operations Network 3"
          },
          {
            "category": "product_version",
            "name": "struts",
            "product": {
              "name": "struts",
              "product_id": "struts"
            }
          },
          {
            "category": "product_version",
            "name": "struts-core",
            "product": {
              "name": "struts-core",
              "product_id": "struts-core",
              "product_identification_helper": {
                "purl": "pkg:maven/org.apache.struts/struts-core"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "struts as a component of Red Hat JBoss Enterprise Application Platform 6",
          "product_id": "red_hat_jboss_enterprise_application_platform_6:struts"
        },
        "product_reference": "struts",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "struts-core as a component of Red Hat JBoss Fuse 6",
          "product_id": "red_hat_jboss_fuse_6:struts-core"
        },
        "product_reference": "struts-core",
        "relates_to_product_reference": "red_hat_jboss_fuse_6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "struts as a component of Red Hat JBoss Fuse Service Works 6",
          "product_id": "red_hat_jboss_fuse_service_works_6:struts"
        },
        "product_reference": "struts",
        "relates_to_product_reference": "red_hat_jboss_fuse_service_works_6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "struts as a component of Red Hat JBoss Operations Network 3",
          "product_id": "red_hat_jboss_operations_network_3:struts"
        },
        "product_reference": "struts",
        "relates_to_product_reference": "red_hat_jboss_operations_network_3"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2020-17530",
      "cwe": {
        "id": "CWE-20",
        "name": "Improper Input Validation"
      },
      "discovery_date": "2020-12-08T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "red_hat_jboss_enterprise_application_platform_6:struts",
            "red_hat_jboss_fuse_6:struts-core",
            "red_hat_jboss_fuse_service_works_6:struts",
            "red_hat_jboss_operations_network_3:struts"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "1905645"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in the Apache Struts frameworks. When forced, some of the tag's attributes perform a double evaluation if a developer applies forced OGNL evaluation by using the %{...} syntax. Using a forced OGNL evaluation on untrusted user input allows an attacker to perform remote code execution and security degradation. The highest threat from this vulnerability is to data confidentiality, integrity as well as system availability.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "struts2: using forced OGNL evaluation on untrusted user input can lead to a RCE and security degradation",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "Apache Struts2 is not compiled, shipped, used, or enabled in Red Hat products. As such, any CVE against Apache Struts2 does not impact currently supported Red Hat products.\n\nThis statement was last revised on 1 Sept 2020.\n\nPrevious statement example: https://bugzilla.redhat.com/show_bug.cgi?id=1469265",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "red_hat_jboss_enterprise_application_platform_6:struts",
          "red_hat_jboss_fuse_6:struts-core",
          "red_hat_jboss_fuse_service_works_6:struts",
          "red_hat_jboss_operations_network_3:struts"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2020-17530"
        },
        {
          "category": "external",
          "summary": "RHBZ#1905645",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1905645"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2020-17530",
          "url": "https://www.cve.org/CVERecord?id=CVE-2020-17530"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2020-17530",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-17530"
        },
        {
          "category": "external",
          "summary": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "release_date": "2020-12-08T00:00:00+00:00",
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "red_hat_jboss_enterprise_application_platform_6:struts",
            "red_hat_jboss_fuse_6:struts-core",
            "red_hat_jboss_fuse_service_works_6:struts",
            "red_hat_jboss_operations_network_3:struts"
          ]
        }
      ],
      "threats": [
        {
          "category": "exploit_status",
          "date": "2021-11-03T00:00:00+00:00",
          "details": "CISA: https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "red_hat_jboss_enterprise_application_platform_6:struts",
            "red_hat_jboss_fuse_6:struts-core",
            "red_hat_jboss_fuse_service_works_6:struts",
            "red_hat_jboss_operations_network_3:struts"
          ]
        }
      ],
      "title": "struts2: using forced OGNL evaluation on untrusted user input can lead to a RCE and security degradation"
    }
  ]
}
Enrichment data
View JSON API Download JSON