Unrated severityNVD Advisory· Published Dec 2, 2021· Updated Sep 16, 2024
Spring SPEL Expression Language Injection
CVE-2021-23258
Description
Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans. SPEL Expression does not have security restrictions, which will cause attackers to execute arbitrary commands remotely (RCE).
Affected products
1- Range: 3.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- docs.craftercms.org/en/3.1/security/advisory.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.