CVE-2021-21307 is an unauthenticated remote code execution (RCE) vulnerability affecting Lucee Server versions prior to 5.3.7.47, 5.3.6.68, or 5.3.5.96. This critical flaw, with a CVSS score of 9.8, allows attackers to execute arbitrary code without authentication, leading to complete compromise of confidentiality, integrity, and availability. Exploit code is publicly available via Metasploit modules and Nuclei templates, and the vulnerability has garnered significant community discussion, indicating high awareness and potential for exploitation. While not currently on CISA's KEV catalog, its high EPSS score and FAUCET Risk Score of 100/100 suggest a high likelihood of future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.3.5.00, < 5.3.5.96CPE matchmatch criteria | cpe:2.3:a:lucee:lucee_server:*:*:*:*:*:*:*:* | ||
>= 5.3.6.00, < 5.3.6.68CPE matchmatch criteria | cpe:2.3:a:lucee:lucee_server:*:*:*:*:*:*:*:* | ||
>= 5.3.7.00, < 5.3.7.47CPE matchmatch criteria | cpe:2.3:a:lucee:lucee_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.