QID 730133
Date Published: 2021-07-08
QID 730133: Lucee Admin Remote Code Execution Vulnerability
Lucee is open source software that implements a lightweight dynamically-typed scripting language for the Java virtual machine, facilitating the rapid development of web applications that compile directly to Java bytecode.
An unauthenticated remote code exploit is available.
Affected Versions:
Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.96
QID Detection Logic:(Unauthenticated)
This QID sends a GET request to /qualys.cfm or /lucee/admin/qualys.cfm a non existent 404 page to check if the target Lucee version.
Successful exploitation of this vulnerability may allow an unauthenticated remote attacker to execute arbitrary code execution on the target system.
Solution
Customers are advised to upgrade to the lucee admins versions 5.3.7.47, 5.3.6.68 or 5.3.5.96 or later. For more information about the vulnerability, refer Lucee Advisory.Workaround:
Block access to the Lucee Administrator as recommended by Lucee Advisory.
Block access to the Lucee Administrator as recommended by Lucee Advisory.
Vendor References
CVEs related to QID 730133
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Lucee Advisory |
|