CRITICAL

CVE-2021-21307

CVSS v3

9.8

CRITICAL

EPSS Score

92.2%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.96 there is an unauthenticated remote code exploit. This is fixed in versions 5.3.7.47, 5.3.6.68 or 5.3.5.96. As a workaround, one can block access to the Lucee Administrator.

Technical details

Published
2/11/2021

Frequently asked questions

What is CVE-2021-21307?

Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.96 there is an unauthenticated remote code exploit. This is fixed in versions 5.3.7.47, 5.3.6.68 or 5.3.5.96. As a workaround, one can block access to the Lucee Administrator.

Is CVE-2021-21307 actively exploited?

Active exploitation of CVE-2021-21307 has not been confirmed. The EPSS score is 92.2%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-21307?

CVE-2021-21307 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2021-21307 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.