CVE-2021-28170

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/05/2021
Last modified:
25/04/2022

Description

In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eclipse:jakarta_expression_language:*:*:*:*:*:*:*:* 3.0.3 (including)
cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:* 2.3.0 (excluding)
cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*