{"id":"CVE-2018-11776","details":"Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.","aliases":["GHSA-cr6j-3jp9-rw65"],"modified":"2026-07-08T05:52:14.446651895Z","published":"2018-08-22T13:29:00.753Z","database_specific":{"unresolved_ranges":[{"vendor_product":"netapp:active_iq_unified_manager","cpes":["cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:vmware_vsphere:*:*","cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:windows:*:*"],"extracted_events":[{"introduced":"7.3"},{"introduced":"9.5"}],"source":"CPE_RANGE"},{"cpes":["cpe:2.3:a:oracle:communications_policy_management:*:*:*:*:*:*:*:*"],"extracted_events":[{"fixed":"12.5.0"}],"source":"CPE_RANGE","vendor_product":"oracle:communications_policy_management"},{"extracted_events":[{"last_affected":"3.4.9.4237"},{"introduced":"4.0.0"},{"last_affected":"4.0.6.5281"},{"introduced":"8.0.0"},{"last_affected":"8.0.2.8191"}],"source":"CPE_RANGE","vendor_product":"oracle:mysql_enterprise_monitor","cpes":["cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*"]},{"extracted_events":[{"introduced":"13.3.0.0"},{"last_affected":"13.3.0.0"},{"introduced":"13.4.0.0"},{"last_affected":"13.4.0.0"}],"source":"CPE_STRING","vendor_product":"oracle:enterprise_manager_base_platform","cpes":["cpe:2.3:a:oracle:enterprise_manager_base_platform:13.3.0.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:enterprise_manager_base_platform:13.4.0.0:*:*:*:*:*:*:*"]}]},"references":[{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-11776"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/172830/Apache-Struts-Remote-Code-Execution.html"},{"type":"ADVISORY","url":"http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-005.txt"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/105125"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1041547"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1041888"},{"type":"ADVISORY","url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0012"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20180822-0001/"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20181018-0002/"},{"type":"ADVISORY","url":"https://www.oracle.com/security-alerts/cpujul2020.html"},{"type":"REPORT","url":"https://cwiki.apache.org/confluence/display/WW/S2-057"},{"type":"FIX","url":"http://www.oracle.com/technetwork/security-advisory/alert-cve-2018-11776-5072787.html"},{"type":"FIX","url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html"},{"type":"FIX","url":"https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html"},{"type":"ARTICLE","url":"https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E"},{"type":"EVIDENCE","url":"https://github.com/hook-s3c/CVE-2018-11776-Python-PoC"},{"type":"EVIDENCE","url":"https://lgtm.com/blog/apache_struts_CVE-2018-11776"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/45260/"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/45262/"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/45367/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/struts","events":[{"introduced":"df365f17ea11e319302f648e86da3188ce1c5656"},{"fixed":"dbcca3512ee1a971cc0b44beac8f6b219a1bb153"},{"introduced":"0"},{"fixed":"eacc002334b42dc808099b12d2ce2a5177cab42d"}],"database_specific":{"cpe":"cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.0.4"},{"fixed":"2.3.35"},{"introduced":"2.5.0"},{"fixed":"2.5.17"}],"source":"CPE_RANGE"}}],"versions":["STRUTS_2_5_16","STRUTS_2_5_15","STRUTS_2_5_14_1","STRUTS_2_5_14","STRUTS_2_5_13","STRUTS_2_3_34","STRUTS_2_3_33","STRUTS_2_5_12","STRUTS_2_5_11","STRUTS_2_3_32","STRUTS_2_5_10","STRUTS_2_5_9","STRUTS_2_5_8","STRUTS_2_5_7","STRUTS_2_5_6","STRUTS_2_5_5","STRUTS_2_5_4","STRUTS_2_3_31","STRUTS_2_5_3","STRUTS_2_3_30","STRUTS_2_3_29","STRUTS_2_3_28","STRUTS_2_3_24_1","STRUTS_2_3_27","STRUTS_2_3_26","STRUTS_2_3_25","STRUTS_2_5_BETA2","STRUTS_2_3_24","STRUTS_2_5_BETA1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-11776.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}