Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1 uses an unintentional expression in a Freemarker tag instead of string literals, which makes it susceptible to remote code execution attacks.
View the template here CVE-2017-12611.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2017-12611