ZeroHour

CVE-2021-28170

PoC ×2
CVSS 3.1
5.3 medium
EPSS
2%p81
Published
()
Modified
Description

In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid.

Vendors
eclipsequarkusoracle
Products
jakarta expression language, quarkus, communications cloud native core policy, weblogic server
Weakness
CWE-20, CWE-917
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.