Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-21307

Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.96 there is an unauthenticated remote code exploit. This is fixed in versions 5.3.7.47, 5.3.6.68 or 5.3.5.96. As a workaround, one can block access to the Lucee Administrator.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.922
EPSS Ranking 99.7%
CVSS Severity
CVSS v3 Score 8.6
CVSS v2 Score 7.5
References
Products affected by CVE-2021-21307


Contact Us

Shodan ® - All rights reserved