CVE-2021-21307
Summary
| CVE | CVE-2021-21307 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-11 19:15:00 UTC |
| Updated | 2021-09-21 16:39:00 UTC |
| Description | Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.96 there is an unauthenticated remote code exploit. This is fixed in versions 5.3.7.47, 5.3.6.68 or 5.3.5.96. As a workaround, one can block access to the Lucee Administrator. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Remote Code Exploit in Lucee Admin · Advisory · lucee/Lucee · GitHub |
CONFIRM |
github.com |
Product |
| Updating Lucee as part of a vulnerability alert response |
MISC |
ciacfug.org |
Patch, Third Party Advisory |
| Security researchers earn $50k after exposing critical flaw in Apple travel portal | The Daily Swig |
MISC |
portswigger.net |
Press/Media Coverage, Third Party Advisory |
| Lucee Administrator imgProcess.cfm Arbitrary File Write ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| writeups/Apple-RCE.md at main · httpvoid/writeups · GitHub |
MISC |
github.com |
Exploit, Third Party Advisory |
| Lucee Vulnerability Alert - November 2020 - blog - Lucee Dev |
MISC |
dev.lucee.org |
Vendor Advisory |
| fixes LDEV-3119 · lucee/Lucee@6208ab7 · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 730133 Lucee Admin Remote Code Execution Vulnerability