cbcvebase.
CVE-2021-28170
published 2021-05-26

CVE-2021-28170: In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if…

medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianjakarta-el-api
eclipsejakarta_expression_language<= 3.0.3
oraclecommunications_cloud_native_core_policy
oracleweblogic_server
quarkusquarkus< 2.3.02.3.0
the_eclipse_foundationjakarta_expression_language_implementationunspecified – 3.0.3

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM