Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-23258

Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans. SPEL Expression does not have security restrictions, which will cause attackers to execute arbitrary commands remotely (RCE).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.3%
CVSS Severity
CVSS v3 Score 4.2
CVSS v2 Score 6.5
Products affected by CVE-2021-23258


Contact Us

Shodan ® - All rights reserved