Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vwjx-mmwm-pwrf

Опубликовано: 05 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 10

Описание

Lucee RCE/XXE Vulnerability

Impact

The Lucee team received a responsible disclosure of a security vulnerability which affects all previous releases of Lucee.

After reviewing the report and confirming the vulnerability, the Lucee team then conducted a further security review and found additional vulnerabilities which have been addressed as part of this this security update.

Patches

Lucee 5.4.3.2 and 5.3.12.1 stable releases have been patched with additional hardening

The older releases, 5.3.7.59., 5.3.8.236 and 5.3.9.173 have also been patched

Any users running older release, should plan to immediately upgrade to the latest stable release

6.0 will have a RC as it's not yet released

Пакеты

Наименование

org.lucee:lucee

maven
Затронутые версииВерсия исправления

>= 5.3.10.79-RC, < 5.3.12.1

5.3.12.1

Наименование

org.lucee:lucee

maven
Затронутые версииВерсия исправления

>= 5.4.0.65-RC, < 5.4.3.2

5.4.3.2

Наименование

org.lucee:lucee

maven
Затронутые версииВерсия исправления

<= 5.3.7.59

Отсутствует

Наименование

org.lucee:lucee

maven
Затронутые версииВерсия исправления

>= 5.3.8.132-RC, < 5.3.8.236

5.3.8.236

Наименование

org.lucee:lucee

maven
Затронутые версииВерсия исправления

>= 5.3.9.113, < 5.3.9.173

5.3.9.173

EPSS

Процентиль: 41%
0.00189
Низкий

10 Critical

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 9.8
nvd
11 месяцев назад

Lucee Server (or simply Lucee) is a dynamic, Java based, tag and scripting language used for rapid web application development. The Lucee REST endpoint is vulnerable to RCE via an XML XXE attack. This vulnerability is fixed in Lucee 5.4.3.2, 5.3.12.1, 5.3.7.59, 5.3.8.236, and 5.3.9.173.

EPSS

Процентиль: 41%
0.00189
Низкий

10 Critical

CVSS3

Дефекты

CWE-611