lucee is vulnerable to XML External Entity (XXE) Attack
98
Critical Risk
Affected versions of this package are vulnerable to XML External Entity (XXE) injection in its REST endpoint. An attacker can exploit this by submitting malicious XML data, potentially leading to arbitrary code execution, data exfiltration, or denial of service.
You are affected if you are using a version that falls within the vulnerable range.
lucee is vulnerable to XML External Entity (XXE) Attack in versions 0.0.1 - 5.3.7.58, 5.3.8.132-RC - 5.3.12.0 and 5.4.0.65-RC - 5.4.3.1.
Upgrade the org.lucee:lucee library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant