Lucee Server (or simply Lucee) is a dynamic, Java based, tag and scripting language used for rapid web application development. The Lucee REST endpoint is vulnerable to RCE via an XML XXE attack. This vulnerability is fixed in Lucee 5.4.3.2, 5.3.12.1, 5.3.7.59, 5.3.8.236, and 5.3.9.173.
History

Thu, 06 Mar 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Mar 2025 15:45:00 +0000

Type Values Removed Values Added
Description Lucee Server (or simply Lucee) is a dynamic, Java based, tag and scripting language used for rapid web application development. The Lucee REST endpoint is vulnerable to RCE via an XML XXE attack. This vulnerability is fixed in Lucee 5.4.3.2, 5.3.12.1, 5.3.7.59, 5.3.8.236, and 5.3.9.173.
Title RCE in Lucee REST endpoint
Weaknesses CWE-611
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-03-05T15:37:55.847Z

Updated: 2025-03-06T21:58:44.944Z

Reserved: 2023-07-24T16:19:28.364Z

Link: CVE-2023-38693

cve-icon Vulnrichment

Updated: 2025-03-06T21:58:40.834Z

cve-icon NVD

Status : Received

Published: 2025-03-05T16:15:37.007

Modified: 2025-03-05T16:15:37.007

Link: CVE-2023-38693

cve-icon Redhat

No data.