CVE-2013-2251 is a critical vulnerability in Apache Struts versions 2.0.0 through 2.3.15, allowing remote attackers to execute arbitrary OGNL expressions by manipulating parameters with specific prefixes. This flaw affects a range of products including those from Apache, Fujitsu, Microsoft, Oracle, and Red Hat. With a CVSS score of 9.8 (Critical), it presents an easily exploitable network-based attack with no authentication required, leading to complete compromise of confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, with readily available exploit code in Metasploit and Nuclei templates, and has garnered significant community discussion and media coverage, indicating its widespread impact and continued relevance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.3, < 1.3.8CPE matchmatch criteria | cpe:2.3:a:apache:archiva:*:*:*:*:*:*:*:* | ||
1.2CPE matchmatch criteria | cpe:2.3:a:apache:archiva:1.2:-:*:*:*:*:*:* | ||
1.2.2CPE matchmatch criteria | cpe:2.3:a:apache:archiva:1.2.2:*:*:*:*:*:*:* | ||
>= 2.0.0, <= 2.3.15CPE matchmatch criteria | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:a:fujitsu:interstage_business_process_manager_analytics:12.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.