Medium severity5.3NVD Advisory· Published May 26, 2021· Updated Jun 17, 2026
CVE-2021-28170
CVE-2021-28170
Description
In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.sun.el:el-riMaven | < 3.0.4 | 3.0.4 |
org.glassfish:jakarta.elMaven | < 3.0.4 | 3.0.4 |
org.glassfish:javax.elMaven | <= 3.0.1-b12 | — |
Affected products
8cpe:2.3:a:eclipse:jakarta_expression_language:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:eclipse:jakarta_expression_language:*:*:*:*:*:*:*:*range: <=3.0.3
- (no CPE)range: unspecified
- cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
- ghsa-coords3 versions
< 3.0.4+ 2 more
- (no CPE)range: < 3.0.4
- (no CPE)range: < 3.0.4
- (no CPE)range: <= 3.0.1-b12
Patches
Vulnerability mechanics
References
9- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party AdvisoryWEB
- github.com/eclipse-ee4j/el-ri/issues/155nvdExploitIssue TrackingThird Party AdvisoryWEB
- securitylab.github.com/advisories/GHSL-2020-021-jakarta-el/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-v6w3-2prq-h95fghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-28170ghsaADVISORY
- securitylab.github.com/advisories/GHSL-2020-021-jakarta-elghsaADVISORY
- github.com/eclipse-ee4j/el-ri/pull/160/commits/b6a3943ac5fba71cbc6719f092e319caa747855bghsaWEB
- security.snyk.io/vuln/SNYK-JAVA-ORGGLASSFISH-1297098ghsaWEB
- security.snyk.io/vuln/SNYK-JAVA-ORGGLASSFISH-2841368ghsaWEB
News mentions
0No linked articles in our index yet.