{"api_version":"1","generated_at":"2026-07-23T14:48:15+00:00","cve":"CVE-2021-21307","urls":{"html":"https://cve.report/CVE-2021-21307","api":"https://cve.report/api/cve/CVE-2021-21307.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-21307","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-21307"},"summary":{"title":"CVE-2021-21307","description":"Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.96 there is an unauthenticated remote code exploit. This is fixed in versions 5.3.7.47, 5.3.6.68 or 5.3.5.96. As a workaround, one can block access to the Lucee Administrator.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2021-02-11 19:15:00","updated_at":"2021-09-21 16:39:00"},"problem_types":["CWE-862"],"metrics":[],"references":[{"url":"https://github.com/lucee/Lucee/security/advisories/GHSA-2xvv-723c-8p7r","name":"https://github.com/lucee/Lucee/security/advisories/GHSA-2xvv-723c-8p7r","refsource":"CONFIRM","tags":["Product"],"title":"Remote Code Exploit in Lucee Admin  · Advisory · lucee/Lucee · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://ciacfug.org/blog/updating-lucee-as-part-of-a-vulnerability-alert-response","name":"http://ciacfug.org/blog/updating-lucee-as-part-of-a-vulnerability-alert-response","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"Updating Lucee as part of a vulnerability alert response","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://portswigger.net/daily-swig/security-researchers-earn-50k-after-exposing-critical-flaw-in-apple-travel-portal","name":"https://portswigger.net/daily-swig/security-researchers-earn-50k-after-exposing-critical-flaw-in-apple-travel-portal","refsource":"MISC","tags":["Press/Media Coverage","Third Party Advisory"],"title":"Security researchers earn $50k after exposing critical flaw in Apple travel portal | The Daily Swig","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/163864/Lucee-Administrator-imgProcess.cfm-Arbitrary-File-Write.html","name":"http://packetstormsecurity.com/files/163864/Lucee-Administrator-imgProcess.cfm-Arbitrary-File-Write.html","refsource":"MISC","tags":[],"title":"Lucee Administrator imgProcess.cfm Arbitrary File Write ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/httpvoid/writeups/blob/main/Apple-RCE.md","name":"https://github.com/httpvoid/writeups/blob/main/Apple-RCE.md","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"writeups/Apple-RCE.md at main · httpvoid/writeups · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://dev.lucee.org/t/lucee-vulnerability-alert-november-2020/7643","name":"https://dev.lucee.org/t/lucee-vulnerability-alert-november-2020/7643","refsource":"MISC","tags":["Vendor Advisory"],"title":"Lucee Vulnerability Alert - November 2020 - blog - Lucee Dev","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/lucee/Lucee/commit/6208ab7c44c61d26c79e0b0af10382899f57e1ca","name":"https://github.com/lucee/Lucee/commit/6208ab7c44c61d26c79e0b0af10382899f57e1ca","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"fixes LDEV-3119 · lucee/Lucee@6208ab7 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-21307","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-21307","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"21307","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"lucee","cpe5":"lucee_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"21307","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"lucee","cpe5":"lucee_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-21307","qid":"730133","title":"Lucee Admin Remote Code Execution Vulnerability"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-advisories@github.com","ID":"CVE-2021-21307","STATE":"PUBLIC","TITLE":"Remote Code Exploit in Lucee Admin"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Lucee","version":{"version_data":[{"version_value":">= 5.3.5.0, < 5.3.5.96"},{"version_value":">= 5.3.6.0, < 5.3.6.68"},{"version_value":">= 5.3.7.0, < 5.3.7.47"}]}}]},"vendor_name":"lucee"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.96 there is an unauthenticated remote code exploit. This is fixed in versions 5.3.7.47, 5.3.6.68 or 5.3.5.96. As a workaround, one can block access to the Lucee Administrator."}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.6,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-862: Missing Authorization"}]}]},"references":{"reference_data":[{"name":"https://github.com/lucee/Lucee/security/advisories/GHSA-2xvv-723c-8p7r","refsource":"CONFIRM","url":"https://github.com/lucee/Lucee/security/advisories/GHSA-2xvv-723c-8p7r"},{"name":"https://github.com/lucee/Lucee/commit/6208ab7c44c61d26c79e0b0af10382899f57e1ca","refsource":"MISC","url":"https://github.com/lucee/Lucee/commit/6208ab7c44c61d26c79e0b0af10382899f57e1ca"},{"name":"https://dev.lucee.org/t/lucee-vulnerability-alert-november-2020/7643","refsource":"MISC","url":"https://dev.lucee.org/t/lucee-vulnerability-alert-november-2020/7643"},{"name":"https://github.com/httpvoid/writeups/blob/main/Apple-RCE.md","refsource":"MISC","url":"https://github.com/httpvoid/writeups/blob/main/Apple-RCE.md"},{"name":"https://portswigger.net/daily-swig/security-researchers-earn-50k-after-exposing-critical-flaw-in-apple-travel-portal","refsource":"MISC","url":"https://portswigger.net/daily-swig/security-researchers-earn-50k-after-exposing-critical-flaw-in-apple-travel-portal"},{"name":"http://ciacfug.org/blog/updating-lucee-as-part-of-a-vulnerability-alert-response","refsource":"MISC","url":"http://ciacfug.org/blog/updating-lucee-as-part-of-a-vulnerability-alert-response"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/163864/Lucee-Administrator-imgProcess.cfm-Arbitrary-File-Write.html","url":"http://packetstormsecurity.com/files/163864/Lucee-Administrator-imgProcess.cfm-Arbitrary-File-Write.html"}]},"source":{"advisory":"GHSA-2xvv-723c-8p7r","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2021-02-11 19:15:00","lastModifiedDate":"2021-09-21 16:39:00","problem_types":["CWE-862"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:lucee:lucee_server:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3.6.00","versionEndExcluding":"5.3.6.68","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:lucee:lucee_server:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3.7.00","versionEndExcluding":"5.3.7.47","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:lucee:lucee_server:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3.5.00","versionEndExcluding":"5.3.5.96","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"21307","Ordinal":"195433","Title":"CVE-2021-21307","CVE":"CVE-2021-21307","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"21307","Ordinal":"1","NoteData":"Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.96 there is an unauthenticated remote code exploit. This is fixed in versions 5.3.7.47, 5.3.6.68 or 5.3.5.96. As a workaround, one can block access to the Lucee Administrator.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"21307","Ordinal":"2","NoteData":"2021-02-11","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"21307","Ordinal":"3","NoteData":"2021-08-17","Type":"Other","Title":"Modified"}]}}}