CVE-2017-5638: Apache Struts Jakarta Multipart RCE
A remote code execution vulnerability in the Jakarta Multipart parser Apache Struts 2 uses for file uploads. A malformed Content-Type header triggers evaluation of an attacker-supplied OGNL expression, letting an unauthenticated attacker run arbitrary commands on the server. Exploitation of this flaw was the initial entry point for the 2017 Equifax breach, which exposed data on roughly 147 million people.
View the authoritative record on NVD ↗Affected software
- Apache Struts 2.3.5 through 2.3.31
- Apache Struts 2.5 through 2.5.10
How it's exploited
Send a file upload request with a malicious OGNL expression embedded in the Content-Type header; the Jakarta Multipart parser evaluates it while building an error message, executing the attacker-supplied command.
Severity
CVE-2017-5638 carries a CVSS 3.0 base score of 10.0, rated Critical. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2017-5638 is categorized under CWE-20, the general weakness pattern behind this specific vulnerability.
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Remediation
Upgrade to Struts 2.3.32 or 2.5.10.1 or later, and where possible switch away from the vulnerable Jakarta-based multipart parser to a non-default implementation.
Frequently asked questions
What is CVE-2017-5638?
A remote code execution vulnerability in the Jakarta Multipart parser Apache Struts 2 uses for file uploads. A malformed Content-Type header triggers evaluation of an attacker-supplied OGNL expression, letting an unauthenticated attacker run arbitrary commands on the server. Exploitation of this flaw was the initial entry point for the 2017 Equifax breach, which exposed data on roughly 147 million people.
How severe is CVE-2017-5638?
CVE-2017-5638 has a CVSS 3.0 base score of 10.0 out of 10, rated Critical.
What software is affected by CVE-2017-5638?
CVE-2017-5638 affects Apache Struts 2.3.5 through 2.3.31; Apache Struts 2.5 through 2.5.10.
How do you fix CVE-2017-5638?
Upgrade to Struts 2.3.32 or 2.5.10.1 or later, and where possible switch away from the vulnerable Jakarta-based multipart parser to a non-default implementation.
Where is the authoritative record for CVE-2017-5638?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2017-5638 at https://nvd.nist.gov/vuln/detail/CVE-2017-5638, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest