Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1 uses an unintentional expression in a Freemarker tag instead of string literals, which makes it susceptible to remote code execution attacks.
id: CVE-2017-12611
info:
name: Apache Struts2 S2-053 - Remote Code Execution
author: pikpikcu
...