
CVE-2017-5638 Apache Struts: The Equifax Breach Flaw
CVE-2017-5638 is a remote code execution vulnerability in Apache Struts 2's Jakarta Multipart parser. By injecting an OGNL expression into the Content-Type header of an HTTP POST request, an unauthenticated attacker can execute arbitrary OS commands. The vulnerability was actively exploited to breach Equifax, exposing 147 million records.
