CVE-2020-17530

All FrameworksApache StrutsCWE-917CVE-2020-17530

CVE-2020-17530

State: PUBLISHED · Published: 2020-12-11 · Updated: 2025-10-21 · Assigner: apache
Description
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2020/17xxx/CVE-2020-17530.json