Apache Struts2 S2-062 is vulnerable to remote code execution. The fix issued for CVE-2020-17530 (S2-061) was incomplete, meaning some of the tag’s attributes could still perform a double evaluation if a developer applied forced OGNL evaluation by using the %{…} syntax.
View the template here CVE-2021-31805.yaml
References:
https://security.netapp.com/advisory/ntap-20220420-0001/