CVE-2020-17530 is an expression-language injection vulnerability in Apache Struts versions 2.0.0 through 2.5.25. Forced OGNL evaluation of raw user-controlled input in tag attributes can cause attacker-supplied OGNL expressions to be evaluated, enabling remote code execution in the context of the Struts application.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
7 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This is a seven-file Maven Java proof-of-concept repository that builds and launches a deliberately vulnerable Apache Struts application for CVE-2020-17530 (S2-061). It is not an exploit client and contains no weaponized OGNL or operating-system command payload; rather, it creates the vulnerable server-side condition needed to test the issue. pom.xml pins struts2-core to 2.5.25, an affected release, and includes embedded Tomcat 8.5.63 dependencies. Main.java starts embedded Tomcat on port 8086 and deploys src/main/webapp at the root context. struts.xml maps /s2061 to nth347.TestAction, whose request-bindable id property is rendered by s2061.jsp as <s:a id="%{id}">. This request-controlled tag attribute is the intended OGNL double-evaluation/injection sink. web.xml registers the StrutsPrepareAndExecuteFilter for all paths, while test.html is only a static test file. The repository therefore serves as a local vulnerable-lab/PoC target capable of demonstrating potentially server-side OGNL and command execution when exercised with a separately supplied crafted request.
This repository contains a Python script (exploit.py) and a README.md file. The script is an exploit for OGNL injection vulnerabilities in Apache Struts2 and Tomcat web applications. It allows an attacker to execute arbitrary system commands on a vulnerable server by sending a specially crafted OGNL payload via an HTTP POST request. The script takes a target URL and a command to execute as arguments. The README provides a brief summary and usage instructions. The exploit is operational, requiring the attacker to specify the target URL and desired command. No specific CVE is referenced, but the exploit targets OGNL injection vulnerabilities in Struts2/Tomcat. The only code file is exploit.py, written in Python, and it is the main entry point for the exploit.
This repository contains a single Metasploit module: 'struts2_multi_eval_ognl.rb', which exploits double OGNL evaluation vulnerabilities in Apache Struts 2 (CVE-2019-0230 and CVE-2020-17530). The module targets web applications that use user-supplied data in tag attributes, allowing remote code execution via crafted HTTP requests. The exploit supports two main payload types: direct Unix command execution and deployment of a Meterpreter reverse shell (Linux dropper). The module is highly configurable, allowing the attacker to specify the target URI, HTTP port, parameter name, and which CVE to exploit. The attack vector is network-based, leveraging HTTP requests to inject malicious OGNL expressions. The code is weaponized, as it is part of the Metasploit framework and supports automated payload delivery and session management. No hardcoded IPs or domains are present; the attacker must supply the target's address and relevant parameters.
This repository contains a proof-of-concept (PoC) exploit for CVE-2020-17530, a remote code execution vulnerability in Apache Struts2 versions 2.0.0 through 2.5.25. The repository consists of two files: a README.md describing the vulnerability and the OGNL payload, and s2-061.py, a Python script that sends a crafted POST request to a Struts2 endpoint. The exploit injects a malicious OGNL expression via the 'name' parameter, which, if successful, results in the execution of an arbitrary command on the server (demonstrated by launching Calculator on macOS). The main attack vector is network-based, targeting a web application endpoint. The script is a straightforward PoC and does not include advanced features such as payload customization or detection evasion.
This repository contains a single Python script, 'struts2-061-poc.py', which is a proof-of-concept exploit for Apache Struts 2 vulnerability S2-061 (CVE-2020-17530). The script targets Struts 2 versions 2.0.0 through 2.5.25 and exploits a remote code execution flaw via OGNL injection in the 'id' parameter of a GET request. The user provides the target URL and a command to execute; the script crafts a URL-encoded payload and sends it to the target, then parses and prints the command output from the response. The script is designed for use against a test environment (such as Vulhub) but can be adapted for real-world exploitation. The only file in the repository is the exploit script, written in Python, and it requires the 'requests' and 'lxml' libraries.
This repository provides two Python scripts targeting the Apache Struts 2 S2-061 vulnerability (CVE-2020-17530), which allows remote code execution via crafted OGNL expressions. The 'struts2-061-poc.py' script is a proof-of-concept that executes arbitrary system commands on a vulnerable server by injecting an OGNL payload through the 'id' parameter in the URL. The 'S2-061-shell.py' script is an operational exploit that establishes a reverse shell to the attacker's machine, encoding the shell command in base64 and delivering it via a similar OGNL injection. Both scripts require the attacker to specify the target URL, and the shell script also requires the attacker's IP and port for the reverse shell. The README provides usage instructions and additional OGNL payloads for exploitation. The repository is focused, with clear entry points and no extraneous files, and is intended for use against test environments or vulnerable Struts 2 instances.
This repository is a proof-of-concept (POC) exploit for CVE-2020-17530, a remote code execution vulnerability in Apache Struts 2 (versions 2.0.0 to 2.5.25) due to unsafe OGNL evaluation. The main file, CVE-2020-17530.py, is a Python script that constructs a malicious OGNL payload to execute arbitrary commands on a vulnerable Struts 2 server. The script takes command-line arguments for the target host, port, URI, form data name, and the command to execute. It sends a crafted HTTP POST request to the specified endpoint, exploiting the vulnerability to run the supplied command on the server. The output of the command is extracted from the HTTP response and displayed. The repository also includes a README with usage instructions and a requirements.txt listing Python dependencies (requests, beautifulsoup4). No hardcoded IPs or domains are present; the target is user-supplied at runtime. The exploit is not part of a framework and is a standalone POC.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.