Remote Code Execution Vulnerability in Lucee Server Software
CVE-2023-38693
9.8CRITICAL
What is CVE-2023-38693?
Lucee Server, a dynamic Java-based scripting language platform, has a vulnerability within its REST endpoint that allows for Remote Code Execution (RCE) via XML External Entity (XXE) attacks. This issue can enable attackers to manipulate the way XML data is processed, potentially leading to unauthorized access or alterations in the system. The vulnerability affects several versions of the Lucee Server and has been addressed in updates including Lucee 5.4.3.2 and other maintenance releases. Users are strongly advised to update to these fixed versions immediately to mitigate risks.
Affected Version(s)
Lucee >= 5.4.0.0, < 5.4.3.2 < 5.4.0.0, 5.4.3.2
Lucee >= 5.3.12.0, < 5.3.12.1 < 5.3.12.0, 5.3.12.1
Lucee < 5.3.7.59 < 5.3.7.59
