← Back to browse · API

CVE-2020-17530

Severity
CRITICAL
CVSS
9.8
EPSS
0.95622
Risk score
58.47
CISA KEV
Yes
PoC
No
Published
2020-12-11
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2022-1073, GHSA-JC35-Q369-45PV
Products
Apache Software Foundation:Apache Struts Struts 2.0.0 - Struts 2.5.25, Apache:Struts
Sources
cisa.gov CVE-2020-17530
euvd EUVD-2022-1073

Description

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.

References