Remote Code Exploit in Lucee Admin
100Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 8.6epss 89%
from disclosure to weapon0 days
Published on NVDFeb 11
1st PoCSep 13
metasploitJan 15
VulnCheck+1021d
exploitation probability
89%top 1% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.96 there is an unauthenticated remote code exploit. This is fixed in versions 5.3.7.47, 5.3.6.68 or 5.3.5.96. As a workaround, one can block access to the Lucee Administrator.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Affected products
lucee · Luceepublic PoCs found — 2
vulncheckvulncheck.com/xdb/db867065c59cunverifiedvulncheckvulncheck.com/xdb/3721f6461545unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://ciacfug.org/blog/updating-lucee-as-part-of-a-vulnerability-alert-responsehttp://packetstormsecurity.com/files/163864/Lucee-Administrator-imgProcess.cfm-Arbitrary-File-Write.htmlhttps://dev.lucee.org/t/lucee-vulnerability-alert-november-2020/7643https://github.com/httpvoid/writeups/blob/main/Apple-RCE.mdhttps://github.com/lucee/Lucee/commit/6208ab7c44c61d26c79e0b0af10382899f57e1cahttps://github.com/lucee/Lucee/security/advisories/GHSA-2xvv-723c-8p7rhttps://portswigger.net/daily-swig/security-researchers-earn-50k-after-exposing-critical-flaw-in-apple-travel-portal