Remote Code Execution Vulnerability in Lucee Server Software
CVE-2023-38693

9.8CRITICAL

Key Information:

Vendor

Lucee

Status
Vendor
CVE Published:
5 March 2025

What is CVE-2023-38693?

Lucee Server, a dynamic Java-based scripting language platform, has a vulnerability within its REST endpoint that allows for Remote Code Execution (RCE) via XML External Entity (XXE) attacks. This issue can enable attackers to manipulate the way XML data is processed, potentially leading to unauthorized access or alterations in the system. The vulnerability affects several versions of the Lucee Server and has been addressed in updates including Lucee 5.4.3.2 and other maintenance releases. Users are strongly advised to update to these fixed versions immediately to mitigate risks.

Affected Version(s)

Lucee >= 5.4.0.0, < 5.4.3.2 < 5.4.0.0, 5.4.3.2

Lucee >= 5.3.12.0, < 5.3.12.1 < 5.3.12.0, 5.3.12.1

Lucee < 5.3.7.59 < 5.3.7.59

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-38693 : Remote Code Execution Vulnerability in Lucee Server Software