CVE-2023-38693

Lucee Server (or simply Lucee) is a dynamic, Java based, tag and scripting language used for rapid web application development. The Lucee REST endpoint is vulnerable to RCE via an XML XXE attack. This vulnerability is fixed in Lucee 5.4.3.2, 5.3.12.1, 5.3.7.59, 5.3.8.236, and 5.3.9.173.
Configurations

No configuration.

History

05 Mar 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-05 16:15

Updated : 2025-03-05 16:15


NVD link : CVE-2023-38693

Mitre link : CVE-2023-38693

CVE.ORG link : CVE-2023-38693


JSON object : View

Products Affected

No product.

CWE
CWE-611

Improper Restriction of XML External Entity Reference