Vulnerability record · CVE-2012-0392 · published 8 January 2012
CVE-2012-0392: Apache Struts CookieInterceptor parameter whitelist bypass enables remote code execution
Apache · Struts
The CookieInterceptor component in Apache Struts before 2.3.1.1 fails to apply the parameter-name whitelist, so a crafted HTTP Cookie header can reach Java static methods and execute arbitrary commands. This is a remote, unauthenticated code execution flaw in a widely deployed web framework, making it a serious risk for any unpatched Struts 2 deployment.
Description
The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method.
AV:N/AC:M/Au:N/C:P/I:P/A:P
Automated analysis
critical priorityUnauthenticated remote code execution in a widely used framework with public exploit code and very high EPSS probability warrants immediate patching.
What it is
The CookieInterceptor component in Apache Struts before 2.3.1.1 fails to apply the parameter-name whitelist, so a crafted HTTP Cookie header can reach Java static methods and execute arbitrary commands. This is a remote, unauthenticated code execution flaw in a widely deployed web framework, making it a serious risk for any unpatched Struts 2 deployment.
Impact
An attacker can execute arbitrary commands on the server hosting the Struts application, leading to full compromise of the application and potentially the underlying host. No credentials are required.
Attack surface
Reached over the network via a crafted HTTP Cookie header sent to a Struts 2 application; the CVSS vector (AV:N/AC:M/Au:N) indicates no authentication is needed, though some attack complexity is present. No user interaction is required.
Exploitation
Public exploit code exists (Exploit-DB 18329 and a dailydave post are tagged Exploit), and EPSS is very high at 0.975 (99.9th percentile), though the CVE is not listed in CISA KEV.
What to do
- Upgrade Apache Struts to 2.3.1.1 or later, which applies the parameter-name whitelist in CookieInterceptor.
- If immediate upgrade is not possible, restrict or block Cookie headers containing suspicious parameter names at a reverse proxy or WAF.
- Remove or disable the CookieInterceptor if it is not required by the application.
- Review server logs for signs of command execution and rotate any credentials or keys exposed on affected hosts.
Detection
- Inspect HTTP request logs for Cookie headers containing parameter names that match Struts action or OGNL-style patterns.
- Monitor for unexpected child processes spawned by the Java/Struts application server.
- Alert on outbound network connections from the Struts host to unusual destinations following HTTP requests.
- Use the public Exploit-DB 18329 payload patterns as signatures in IDS/WAF rules.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-0392 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-0392), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.