← All CVEs

CVE-2021-21307

high · 8.6

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.96 there is an unauthenticated remote code exploit. This is fixed in versions 5.3.7.47, 5.3.6.68 or 5.3.5.96. As a workaround, one can block access to the Lucee Administrator.

8.6
CVSS
89.2%
EPSS (exploit prob.)
100th
EPSS percentile
2021-02-11
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Weaknesses

CWE-862

Affected products

VendorProductAffected versions
luceelucee_server>= 5.3.5.00, < 5.3.5.96
luceelucee_server>= 5.3.6.00, < 5.3.6.68
luceelucee_server>= 5.3.7.00, < 5.3.7.47

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-21307