CVE-2023-38693 Information
Mar 07, 2025
cve
Description
Lucee Server (or simply Lucee) is a dynamic Java based tag and scripting language used for rapid web application development. The Lucee REST endpoint is vulnerable to RCE via an XML XXE attack. This vulnerability is fixed in Lucee 5.4.3.2 5.3.12.1 5.3.7.59 5.3.8.236 and 5.3.9.173.
Reference
https://github.com/lucee/Lucee/security/advisories/GHSA-vwjx-mmwm-pwrf
Share on: