Potential OGNL Injection Exploitation In JVM Based Application
Description
Detects potential OGNL Injection exploitation, which may lead to RCE. OGNL is an expression language that is supported in many JVM based systems. OGNL Injection is the reason for some high profile RCE's such as Apache Struts (CVE-2017-5638) and Confluence (CVE-2022-26134)
Query · sigma
keywords: - org.apache.commons.ognl.OgnlException - ExpressionSyntaxException condition: keywords
Known false positives
- Application bugs