Help Center/ Web Application Firewall/ FAQs/ About WAF/ Can WAF Defend Against the Apache Struts2 Remote Code Execution Vulnerability (CVE-2021-31805)?
Updated on 2025-10-21 GMT+08:00

Can WAF Defend Against the Apache Struts2 Remote Code Execution Vulnerability (CVE-2021-31805)?

Yes. WAF basic web protection rules can defend against the Apache Struts2 remote code execution vulnerability (CVE-2021-31805).

Follow the procedure below to complete the configuration.

Configuration Procedure

  1. Buy WAF.
  2. Add the website domain name to WAF and resolve it to WAF. For details, see Connecting Your Website to WAF (Cloud Mode - CNAME Access).
  3. In the Basic Web Protection configuration area, set the protective action to Block. For details, see Configuring Basic Web Protection Rules.