Website Security & Threat Management
Protection from Struts Remote Code Execution Vulnerability (S2-057)

Protection from Struts Remote Code Execution Vulnerability (S2-057)

9/5/2018 · Richard Sommerville

What this post added

This post details the immediate mitigation of the Apache Struts S2-057 vulnerability by Cloudflare's Web Application Firewall (WAF). It explains the nature of OGNL expressions used in RCE payloads and how S2-057 differs from previous Struts vulnerabilities by exploiting the 'namespace' parameter. Cloudflare's WAF was updated with specific rules to block these attacks, leveraging general OGNL signature rules and targeted payload vector rules. The post also shares observed attack patterns, including probing and attempts to execute commands.

Read the original post ↗