← Back to browse · API

CVE-2017-9791

Severity
CRITICAL
CVSS
9.8
EPSS
0.98817
Risk score
59.59
CISA KEV
Yes
PoC
No
Published
2017-07-10
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2022-1954, GHSA-29RM-6752-GVWV
Products
Apache Software Foundation:Apache Struts 2.1.x series, Apache Software Foundation:Apache Struts 2.3.x series, Apache:Struts 1
Sources
cisa.gov CVE-2017-9791
euvd EUVD-2022-1954

Description

The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.

References