S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-21307 Scanner

CVE-2021-21307 scanner - Remote Code Execution (RCE) vulnerability in Lucee Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-21307
9.8
CVSShigh
Exploitable remotely over the internet · no authentication required.

Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.96 there is an unauthenticated remote code exploit. This is fixed in versions 5.3.7.47, 5.3.6.68 or 5.3.5.96. As a workaround, one can block access to the Lucee Administrator.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Luceeby lucee
>= 5.3.5.0, < 5.3.5.96
Updated Aug 21, 2026View on NVD →
Detail

Lucee Server is a powerful and dynamic web server used for rapid web application development. It is Java-based and provides a versatile tag and scripting language that enables developers to create web applications with ease. The primary purpose of Lucee Server is to facilitate the development of web applications that can run efficiently and seamlessly across different platforms and operating systems.

The CVE-2021-21307 vulnerability is a security flaw that has been detected in Lucee Server. This vulnerability allows remote attackers to execute arbitrary code without any authentication. In other words, anyone can exploit this vulnerability if they have access to the internet. This vulnerability is particularly concerning because it can lead to significant data breaches and other types of cyber attacks that can compromise the security and integrity of web applications powered by Lucee Server.

If this vulnerability is exploited, it can lead to several adverse consequences. Hackers can gain unauthorized access to sensitive information, delete, modify, or steal data, and even launch malicious cyber attacks that can harm the infrastructure of the web application. The consequences of this vulnerability can be severe and long-lasting, causing significant damage to businesses, organizations, and individuals.

In conclusion, the CVE-2021-21307 vulnerability detected in Lucee Server is a severe security flaw that can compromise the integrity and security of web applications. To protect against this vulnerability, using a web application firewall, updating to the latest version of Lucee Server, and implementing strong access controls and authentication mechanisms are essential. With the help of a reliable security platform such as s4e.io, IT professionals and organizations can stay informed and up-to-date on the latest vulnerabilities and security threats, making digital assets protected from these threats.

 

REFERENCES

Solution Advice

Precautions can be taken to protect against this vulnerability. The following are some of the measures that can be implemented to safeguard web applications powered by Lucee Server:

  • Update to the latest Lucee Server version (5.3.7.47, 5.3.6.68, or 5.3.5.96) that fixes the vulnerability.
  • Block access to Lucee Administrator if you cannot update to the latest version.
  • Use a web application firewall to detect and mitigate malicious attempts to exploit this vulnerability.
  • Utilize strong authentication mechanisms that require multi-factor authentication.
  • Employ strong access controls that ensure only authorized persons have access to sensitive information.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-21307 scanner - Remote Code Execution (RCE) vulnerability in Lucee Server | S4E