Vulnerability record · CVE-2013-4212 · published 7 December 2013
CVE-2013-4212: Apache Roller OGNL injection in ActionSupport getText methods
Apache · Roller
Apache Roller before 5.0.2 passes attacker-controlled parameters into OGNL expressions inside certain getText methods of the ActionSupport controller, allowing remote code execution. The flaw is reachable through the roller-ui/login.rol endpoint, as shown by the pageTitle parameter in the !getPageTitle sub-URL. It matters because a public exploit exists and the affected component is a web-facing application.
Description
Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions via the first or second parameter, as demonstrated by the pageTitle parameter in the !getPageTitle sub-URL to roller-ui/login.rol, which uses a subclass of UIAction, aka "OGNL Injection."
AV:N/AC:M/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote code execution with a public exploit and very high EPSS, though the CVSS v2 score is only 6.8 and no KEV listing exists.
What it is
Apache Roller before 5.0.2 passes attacker-controlled parameters into OGNL expressions inside certain getText methods of the ActionSupport controller, allowing remote code execution. The flaw is reachable through the roller-ui/login.rol endpoint, as shown by the pageTitle parameter in the !getPageTitle sub-URL. It matters because a public exploit exists and the affected component is a web-facing application.
Impact
An attacker can execute arbitrary OGNL expressions, which in this context means arbitrary code execution on the Roller server. That gives full control of the application process and its data.
Attack surface
Reached over the network via HTTP requests to roller-ui/login.rol using crafted parameters such as pageTitle. The CVSS vector shows no authentication required (Au:N) but medium access complexity (AC:M); no user interaction is indicated.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.81, 99.6th percentile) and an Exploit-DB entry is referenced, indicating public exploit code is available.
What to do
- Upgrade Apache Roller to 5.0.2 or later, which the vendor patch reference addresses.
- If immediate upgrade is not possible, restrict network access to roller-ui endpoints and login.rol to trusted users.
- Review and harden any custom UIAction subclasses that pass request parameters into getText or OGNL evaluation.
- Monitor for and block OGNL expression patterns in request parameters at the WAF or reverse proxy.
- Confirm no unauthorized changes to the Roller application or host after exposure.
Detection
- Search web logs for requests to roller-ui/login.rol with unusual pageTitle or other parameter values containing OGNL syntax such as @, #, or method calls.
- Alert on OGNL-like strings in HTTP query strings or POST bodies reaching Roller.
- Monitor the Roller process for unexpected child processes or outbound connections.
- Review application and system logs for errors or stack traces referencing OGNL or getText around suspicious requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-4212 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-4212), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.