Apache Struts 2의 2.3.32 이전 2.3.x 및 2.5.10.1 이전 2.5.x에 있는 Jakarta Multipart parser는 파일 업로드 시도 중 예외 처리와 오류 메시지 생성이 잘못되어 있어, 원격 공격자가 조작된 Content-Type, Content-Disposition 또는 Content-Length HTTP 헤더를 통해 임의 명령을 실행할 수 있습니다. 이는 2017년 3월에 #cmd= 문자열을 포함한 Content-Type 헤더를 사용하여 실제로 악용되었습니다.
Apache Struts 2의 2.3.32 이전 2.3.x 및 2.5.10.1 이전 2.5.x에 있는 Jakarta Multipart parser는 파일 업로드 시도 중 예외 처리와 오류 메시지 생성이 잘못되어 있어, 원격 공격자가 조작된 Content-Type, Content-Disposition 또는 Content-Length HTTP 헤더를 통해 임의 명령을 실행할 수 있습니다. 이는 2017년 3월에 #cmd= 문자열을 포함한 Content-Type 헤더를 사용하여 실제로 악용되었습니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
영향 제품·버전
제품 Apache Struts
영향 버전 Apache Struts 2.3.x before 2.3.32, 2.5.x before 2.5.10.1, >= 2.2.3 < 2.3.32, >= 2.5.0 < 2.5.10.1, 7.7.1.6, 7.8.1.0, 9.1.0, 10.0.0, 10.1.0, 10.2.0, 10.5.0, 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0, < 6.6.5