9.8

CVE-2021-21307

Medienbericht
Exploit

Remote Code Exploit in Lucee Admin

Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.96 there is an unauthenticated remote code exploit. This is fixed in versions 5.3.7.47, 5.3.6.68 or 5.3.5.96. As a workaround, one can block access to the Lucee Administrator.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LuceeLucee Server Version >= 5.3.5.00 < 5.3.5.96
LuceeLucee Server Version >= 5.3.6.00 < 5.3.6.68
LuceeLucee Server Version >= 5.3.7.00 < 5.3.7.47
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 89.19% 0.998
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
security-advisories@github.com 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

http://ciacfug.org/blog/updating-lucee-as-part-of-a-vulnerability-alert-response
Patch
Third Party Advisory
http://packetstormsecurity.com/files/163864/Lucee-Administrator-imgProcess.cfm-Arbitrary-File-Write.html
Third Party Advisory
Exploit
VDB Entry
https://dev.lucee.org/t/lucee-vulnerability-alert-november-2020/7643
Vendor Advisory
https://github.com/httpvoid/writeups/blob/main/Apple-RCE.md
Third Party Advisory
Exploit
https://github.com/lucee/Lucee/commit/6208ab7c44c61d26c79e0b0af10382899f57e1ca
Patch
Third Party Advisory
https://github.com/lucee/Lucee/security/advisories/GHSA-2xvv-723c-8p7r
Product
https://portswigger.net/daily-swig/security-researchers-earn-50k-after-exposing-critical-flaw-in-apple-travel-portal
Third Party Advisory
Press/Media Coverage