You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Struts 2.5.13应用被检测到Expression Language Injection漏洞求助

Fixing Expression Language Injection in Struts 2.5.13 (Contrast Security Report)

Hey there, let's tackle this EL Injection issue you're facing with your Struts 2.5.13 app, specifically on the /App/edit.action endpoint with the abc parameter. From the stack trace you shared, the problem is rooted in OGNL expression parsing during parameter handling—let's break down the fixes step by step:

Why This Happens

Even though Struts 2.5.13 is a relatively recent version, the stack trace shows the ParametersInterceptor is passing the abc parameter value through OGNL's parsing pipeline (ognl.Ognl.parseExpression). This can happen if:

  • Your app has unsafe OGNL configuration flags enabled
  • Input validation for the abc parameter is missing or insufficient
  • You're using an incompatible or outdated OGNL dependency
  • Dynamic method invocation or static method access is inadvertently enabled

Step-by-Step Solutions

1. Upgrade to the Latest Secure Struts 2.5.x Version

Struts 2.5.13 has had several critical security patches released after it. Upgrade to the most recent stable version in the 2.5.x branch (e.g., 2.5.30 or later)—these releases include targeted fixes for OGNL injection vectors that might be exploited here.

2. Lock Down OGNL Configuration in struts.xml

Check your Struts configuration and ensure these security-focused constants are set correctly:

<!-- Disable static method access (confirm it's not overridden to true) -->
<constant name="struts.ognl.allowStaticMethodAccess" value="false"/>

<!-- Disable dynamic method invocation to block arbitrary method calls -->
<constant name="struts.enable.DynamicMethodInvocation" value="false"/>

<!-- Restrict allowed HTTP methods to only what your app actually uses -->
<constant name="struts.parameters.allowedMethods" value="POST,GET"/>

3. Add Strict Input Validation for the abc Parameter

Since the vulnerability is tied directly to the abc parameter, implement strict validation rules:

  • If abc is supposed to be a numeric value, validate it with numeric-only checks
  • If it's a string, block OGNL special characters like #, $, %, {, } and restrict length to expected ranges
  • Use Struts' built-in validation framework (XML-based or annotation-based) to enforce these rules before the parameter reaches OGNL processing.

4. Verify OGNL Dependency Compatibility

Struts 2.5.13 requires a specific OGNL version (typically 3.1.19). Ensure your project isn't pulling in a conflicting or outdated OGNL JAR. Check your build file (Maven/Gradle) to confirm the OGNL dependency is managed by Struts' BOM or matches the version bundled with your Struts release.

5. Validate Interceptor Stack Configuration

Make sure your action's interceptor stack includes standard security interceptors:

  • Keep the default params interceptor (avoid custom modified versions that bypass sanitization)
  • Include the validation interceptor to enforce input rules early in the request flow
  • Remove any custom interceptors that might bypass Struts' built-in parameter safety checks.

Stack Trace Context

Looking at your provided stack trace, the critical flow confirming the issue is:

ognl.Ognl.parseExpression(Ognl.java:110)
com.opensymphony.xwork2.ognl.OgnlUtil.compileAndExecute(OgnlUtil.java:397)
com.opensymphony.xwork2.ognl.OgnlUtil.setValue(OgnlUtil.java:310)
com.opensymphony.xwork2.ognl.OgnlValueStack.trySetValue(OgnlValueStack.java:188)
com.opensymphony.xwork2.interceptor.ParametersInterceptor.setParameters(ParametersInterceptor.java:211)

This shows the abc parameter's value is being parsed as an OGNL expression. The fixes above will block this unintended parsing by either securing the OGNL environment or sanitizing input before it gets processed.

内容的提问来源于stack exchange,提问作者vikrant vij

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 06:41:00