CVE-2018-11776 is a critical Remote Code Execution (RCE) vulnerability affecting Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16, specifically when the alwaysSelectFullNamespace option is enabled and certain conditions regarding namespaces in results or URL tags are met. This vulnerability carries a high CVSS score of 8.1, indicating a severe risk with a network attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, as evidenced by its presence in the KEV catalog and numerous public exploit modules, and has garnered significant community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.4, < 2.3.35CPE matchmatch criteria | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* | ||
>= 2.5.0, < 2.5.17CPE matchmatch criteria | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* | ||
>= 7.3CPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:windows:*:* | ||
>= 9.5CPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:vmware_vsphere:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.