Struts 2.5.13应用被检测到Expression Language Injection漏洞求助
Hey there, let's tackle this EL Injection issue you're facing with your Struts 2.5.13 app, specifically on the /App/edit.action endpoint with the abc parameter. From the stack trace you shared, the problem is rooted in OGNL expression parsing during parameter handling—let's break down the fixes step by step:
Why This Happens
Even though Struts 2.5.13 is a relatively recent version, the stack trace shows the ParametersInterceptor is passing the abc parameter value through OGNL's parsing pipeline (ognl.Ognl.parseExpression). This can happen if:
- Your app has unsafe OGNL configuration flags enabled
- Input validation for the
abcparameter is missing or insufficient - You're using an incompatible or outdated OGNL dependency
- Dynamic method invocation or static method access is inadvertently enabled
Step-by-Step Solutions
1. Upgrade to the Latest Secure Struts 2.5.x Version
Struts 2.5.13 has had several critical security patches released after it. Upgrade to the most recent stable version in the 2.5.x branch (e.g., 2.5.30 or later)—these releases include targeted fixes for OGNL injection vectors that might be exploited here.
2. Lock Down OGNL Configuration in struts.xml
Check your Struts configuration and ensure these security-focused constants are set correctly:
<!-- Disable static method access (confirm it's not overridden to true) --> <constant name="struts.ognl.allowStaticMethodAccess" value="false"/> <!-- Disable dynamic method invocation to block arbitrary method calls --> <constant name="struts.enable.DynamicMethodInvocation" value="false"/> <!-- Restrict allowed HTTP methods to only what your app actually uses --> <constant name="struts.parameters.allowedMethods" value="POST,GET"/>
3. Add Strict Input Validation for the abc Parameter
Since the vulnerability is tied directly to the abc parameter, implement strict validation rules:
- If
abcis supposed to be a numeric value, validate it with numeric-only checks - If it's a string, block OGNL special characters like
#,$,%,{,}and restrict length to expected ranges - Use Struts' built-in validation framework (XML-based or annotation-based) to enforce these rules before the parameter reaches OGNL processing.
4. Verify OGNL Dependency Compatibility
Struts 2.5.13 requires a specific OGNL version (typically 3.1.19). Ensure your project isn't pulling in a conflicting or outdated OGNL JAR. Check your build file (Maven/Gradle) to confirm the OGNL dependency is managed by Struts' BOM or matches the version bundled with your Struts release.
5. Validate Interceptor Stack Configuration
Make sure your action's interceptor stack includes standard security interceptors:
- Keep the default
paramsinterceptor (avoid custom modified versions that bypass sanitization) - Include the
validationinterceptor to enforce input rules early in the request flow - Remove any custom interceptors that might bypass Struts' built-in parameter safety checks.
Stack Trace Context
Looking at your provided stack trace, the critical flow confirming the issue is:
ognl.Ognl.parseExpression(Ognl.java:110) com.opensymphony.xwork2.ognl.OgnlUtil.compileAndExecute(OgnlUtil.java:397) com.opensymphony.xwork2.ognl.OgnlUtil.setValue(OgnlUtil.java:310) com.opensymphony.xwork2.ognl.OgnlValueStack.trySetValue(OgnlValueStack.java:188) com.opensymphony.xwork2.interceptor.ParametersInterceptor.setParameters(ParametersInterceptor.java:211)
This shows the abc parameter's value is being parsed as an OGNL expression. The fixes above will block this unintended parsing by either securing the OGNL environment or sanitizing input before it gets processed.
内容的提问来源于stack exchange,提问作者vikrant vij

