CVE-2021-21307
Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 89.2%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.96 there is an unauthenticated remote code exploit. This is fixed in versions 5.3.7.47, 5.3.6.68 or 5.3.5.96. As a workaround, one can block access to the Lucee Administrator.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 89.19% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- lucee/lucee server
- Source
- security-advisories@github.com
References
- http://ciacfug.org/blog/updating-lucee-as-part-of-a-vulnerability-alert-responsePatch, Third Party Advisory
- http://packetstormsecurity.com/files/163864/Lucee-Administrator-imgProcess.cfm-Arbitrary-File-Write.htmlExploit, Third Party Advisory, VDB Entry
- https://dev.lucee.org/t/lucee-vulnerability-alert-november-2020/7643Vendor Advisory
- https://github.com/httpvoid/writeups/blob/main/Apple-RCE.mdExploit, Third Party Advisory
- https://github.com/lucee/Lucee/commit/6208ab7c44c61d26c79e0b0af10382899f57e1caPatch, Third Party Advisory
- https://github.com/lucee/Lucee/security/advisories/GHSA-2xvv-723c-8p7rProduct
- https://portswigger.net/daily-swig/security-researchers-earn-50k-after-exposing-critical-flaw-in-apple-travel-portalPress/Media Coverage, Third Party Advisory
- http://ciacfug.org/blog/updating-lucee-as-part-of-a-vulnerability-alert-responsePatch, Third Party Advisory
- http://packetstormsecurity.com/files/163864/Lucee-Administrator-imgProcess.cfm-Arbitrary-File-Write.htmlExploit, Third Party Advisory, VDB Entry
- https://dev.lucee.org/t/lucee-vulnerability-alert-november-2020/7643Vendor Advisory
- https://github.com/httpvoid/writeups/blob/main/Apple-RCE.mdExploit, Third Party Advisory
- https://github.com/lucee/Lucee/commit/6208ab7c44c61d26c79e0b0af10382899f57e1caPatch, Third Party Advisory
- https://github.com/lucee/Lucee/security/advisories/GHSA-2xvv-723c-8p7rProduct
- https://portswigger.net/daily-swig/security-researchers-earn-50k-after-exposing-critical-flaw-in-apple-travel-portalPress/Media Coverage, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.