CVE-2023-38693 is a critical Remote Code Execution (RCE) vulnerability affecting Lucee Server, a Java-based web application development platform. The vulnerability stems from an XML External Entity (XXE) attack vector within the Lucee REST endpoint. With a CVSS score of 9.8, this flaw allows unauthenticated attackers to achieve full compromise (confidentiality, integrity, availability) with low attack complexity over the network. While no public exploit intelligence or active exploitation has been observed, and community discussion is minimal, the high FAUCET Risk Score of 87/100 indicates significant potential danger. Patches are available in Lucee versions 5.4.3.2, 5.3.12.1, 5.3.7.59, 5.3.8.236, and 5.3.9.173.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Lucee | Lucee | < 5.3.7.59, >= 5.3.12.0, < 5.3.12.1, >= 5.3.8.0, < 5.3.8.236, >= 5.3.9.0, < 5.3.9.173, >= 5.4.0.0, < 5.4.3.2CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.