CVE-2010-1870 describes a critical vulnerability in the OGNL expression evaluation capability within XWork, affecting Apache Struts versions 2.0.0 through 2.1.8.1, and consequently products like Atlassian Fisheye and Crucible. This flaw allows remote attackers to bypass security mechanisms and modify server-side context objects through various OGNL context variables, leading to potential remote code execution. The vulnerability carries a CVSS score of 5.0, indicating a medium severity, but its exploitability is high due to a low attack complexity and no authentication required (AV:N/AC:L/Au:N). The potential impact is primarily integrity (I:P), allowing unauthorized modification of data. However, the high EPSS score (0.92419) and FAUCET Risk Score (99/100) suggest a much higher real-world risk, likely due to the potential for remote code execution. This vulnerability is actively exploited, with multiple Metasploit modules and ExploitDB entries demonstrating remote command execution capabilities. Community discussion and media coverage further highlight its significance, indicating widespread awareness and targeting by threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.0CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.0.0:*:*:*:*:*:*:* | ||
2.0.1CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.0.1:*:*:*:*:*:*:* | ||
2.0.2CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.0.2:*:*:*:*:*:*:* | ||
2.0.3CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.0.3:*:*:*:*:*:*:* | ||
2.0.4CPE matchmatch criteria | cpe:2.3:a:apache:struts:2.0.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.