Apache Struts 2 contained a remote code execution flaw, CVE-2017-5638, in the Jakarta Multipart parser that allowed attackers to run arbitrary commands by sending crafted HTTP file-upload headers, including malicious Content-Type, Content-Disposition, or Content-Length values. The vulnerability affected Struts 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1, and the CVE record notes that exploitation was observed in the wild, including attacks using a Content-Type header containing a #cmd= string.
The Apache Software Foundation highlighted CVE-2017-5638 as one of the notable exploitation-related cases in its annual security reporting, which summarized hundreds of vulnerability reports handled across more than 340 Apache projects. ASF said its 2020 security operations processed 18,000 security-related emails down to 946 non-spam threads, tracked 376 new vulnerability reports across 101 top-level projects, and assigned 151 CVE identifiers from 341 closed reports, underscoring both the scale of Apache’s disclosure workload and the continued significance of high-impact flaws such as the Struts RCE.

See which actors are running it and whether you're in range.
9 events from the most recent confirmed update back to the earliest known activity.
The CVE record for Apache Struts vulnerability CVE-2017-5638 was updated by the Apache Software Foundation as CNA.
As of January 1, 2021, ASF said 35 of the 376 vulnerability reports it received during 2020 were still under triage, while the remaining closed reports had produced 151 CVE assignments.
In December 2020, ASF became the first organization to obtain a live CVE name using the CVE project's new automation API, shifting from pre-requested CVE pools to on-demand allocation.
In November 2020, the Apache Software Foundation released an internal tool to help projects edit, validate, and submit CVE entries to MITRE, aiming to reduce delays from legacy-format rejections.
ASF reported that CISA's Top 10 Routinely Exploited Vulnerabilities list in May 2020 included Apache Struts 2 remote code execution vulnerability CVE-2017-5638.
Apache Tomcat vulnerability CVE-2020-1938, known as Ghostcat, gained press attention in February 2020. The issue affected Tomcat installations exposing an unprotected AJP Connector to untrusted networks.
MITRE published the CVE record for CVE-2017-5638, documenting the Apache Struts Jakarta Multipart parser remote code execution flaw and affected versions.
Apache published a security advisory for the Struts Jakarta Multipart parser remote code execution flaw CVE-2017-5638 and said versions 2.3.32 and 2.5.10.1 or later were not vulnerable. The advisory recommended immediate upgrading or applying the documented workaround.
The CVE record states that Apache Struts remote code execution vulnerability CVE-2017-5638 was exploited in the wild in March 2017, including attacks using a crafted Content-Type header containing a #cmd= string.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcelists.apache.org
Open sources.apache.org
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.