CVE-2021-31805 is a remote code execution vulnerability in Apache Struts caused by an incomplete fix for CVE-2020-17530. In Apache Struts versions 2.0.0 through 2.5.29, some tag attributes can still be subjected to double evaluation when a developer explicitly forces OGNL evaluation with the %{...} syntax. If untrusted user-controlled input is passed into those attributes and forced OGNL evaluation is applied, attacker-supplied OGNL expressions may be interpreted and executed. The issue affects applications that use vulnerable Struts tags in an unsafe manner, resulting in expression injection and potential arbitrary code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This seven-file Java/Maven repository is a local proof-of-concept vulnerable application rather than a standalone remote exploit client. `pom.xml` identifies the project as CVE-2021-31805 and pins `struts2-core` to Apache Struts 2.5.29, a version targeted by S2-062/CVE-2021-31805. `Main.java` starts an embedded Tomcat 8.5.63 instance on port 8086 and deploys `src/main/webapp` at the root context. Struts configuration exposes the `s2062` action, backed by `TestAction`, whose writable `name` property is rendered in `s2062.jsp` via `<s:label name="%{name}"/>`. This source-to-sink pattern is intended to demonstrate unsafe OGNL evaluation of attacker-controlled action data. No concrete OGNL command payload, callback address, shell, persistence mechanism, or outbound network endpoint is embedded in the repository. The web.xml display name references CVE-2020-17530/S2-061, but that is inconsistent with the declared artifact, Struts 2.5.29 dependency, and JSP title; the implementation most plausibly targets CVE-2021-31805/S2-062. Supporting files are Struts/web deployment XML, the JSP view, and a trivial `test.html` page.
This repository contains a Python proof-of-concept and exploit for CVE-2021-31805, a remote code execution vulnerability in Apache Struts 2 (versions 2.0.0 through 2.5.29). The main file, 'CVE_2021_31805_POC_EXP.py', is a Pocsuite3-compatible exploit module. It crafts a multipart/form-data POST request with a malicious OGNL expression in the 'id' field, exploiting incomplete patching of a previous vulnerability (CVE-2020-17530). The exploit allows an attacker to execute arbitrary system commands on the vulnerable server. The command to execute can be specified by the user, and the exploit will return the output of the command if successful. The README provides usage instructions for both verification and exploitation modes. The code is operational and can be used for both detection and exploitation, depending on the options provided. No hardcoded IPs, domains, or external endpoints are present; the exploit targets user-supplied URLs. The repository is structured with a single exploit script and a README file.
This repository is a Go-based exploit and proof-of-concept tool targeting Apache Struts2 remote command execution vulnerabilities CVE-2021-31805 (S2-062) and CVE-2020-17530 (S2-061). The tool allows users to test for and exploit these vulnerabilities by sending specially crafted OGNL expressions to a target URL, resulting in arbitrary command execution on the server. It supports both direct output (if the server returns command output) and out-of-band DNS-based verification using ceye.io, which requires configuration in ceye.ini. The main entry point is main.go, which parses command-line arguments for the target URL, mode (detection or exploitation), Struts2 version, OS type, and parameter name. The code is modular, with ceye.go handling DNS-based checks, common.go providing utility functions and payload construction, and main.go orchestrating the exploit flow. The repository is operational and can be used for both detection and exploitation, provided the user has the necessary configuration for DNS-based checks.
This repository provides two Python scripts for exploiting the Apache Struts 2 S2-062 (CVE-2021-31805) remote code execution vulnerability. The main exploit script, 's2-062.py', allows the user to send a crafted HTTP POST request to a target URL, injecting a malicious OGNL expression that results in arbitrary command execution on the server. The script supports both proof-of-concept (POC) mode (which attempts to detect the vulnerability) and exploit mode (which executes a user-supplied command). The second script, 'Dnslog_s2_062.py', enhances detection for targets that do not return command output by leveraging the dnslog.cn service. It generates a unique DNS domain and monitors for DNS queries triggered by the exploit, indicating successful code execution even in blind scenarios. Both scripts require the user to specify the target URL and, optionally, the parameter to exploit (default is 'id'). The payload is customizable, and the exploit is operational, capable of executing arbitrary commands. The repository is structured for practical exploitation and detection of S2-062 in real-world environments.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.