Vulnerability record · CVE-2019-0230 · published 14 September 2020
CVE-2019-0230: Apache Struts 2 forced double OGNL evaluation enables remote code execution
Apache · Struts
Apache Struts versions 2.0.0 through 2.5.20 force double OGNL evaluation when tag attributes are evaluated on raw user input, which can lead to remote code execution. The flaw is network-reachable with no privileges or user interaction required, so any exposed Struts application using affected tag attributes is a candidate target.
Description
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network-only, unauthenticated access and public exploit references makes this a top remediation priority despite no KEV listing.
What it is
Apache Struts versions 2.0.0 through 2.5.20 force double OGNL evaluation when tag attributes are evaluated on raw user input, which can lead to remote code execution. The flaw is network-reachable with no privileges or user interaction required, so any exposed Struts application using affected tag attributes is a candidate target.
Impact
An unauthenticated attacker can execute arbitrary code in the context of the application server, leading to full compromise of confidentiality, integrity and availability.
Attack surface
Reached over the network via HTTP requests that place crafted input into Struts tag attributes subject to forced double OGNL evaluation. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV, but EPSS is 0.97399 (99.895th percentile) and multiple references are tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade Apache Struts to a version above 2.5.20 (see the S2-059 vendor advisory for the fixed release).
- Apply the Oracle CPU patches (Jan 2021, Apr 2021, Oct 2021) for affected Oracle products that bundle Struts.
- Avoid passing raw, unvalidated user input into Struts tag attributes; validate and encode input at the boundary.
- If immediate upgrade is not possible, restrict network access to Struts application endpoints and monitor for OGNL-style payloads.
- Inventory applications and dependencies for Struts 2.0.0 through 2.5.20, including third-party products that embed it.
Detection
- Inspect HTTP request parameters and headers for OGNL expression syntax (e.g. %{, ${, #, @) reaching Struts tag attributes.
- Monitor web and application logs for unexpected errors or stack traces from OGNL evaluation.
- Alert on outbound connections or process spawning from the Java application server that are not part of normal behavior.
- Use WAF or IDS signatures for known Struts OGNL exploitation patterns and review hits against affected endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-0230 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-0230), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.