Intel

AIKIDO-2025-10156

lucee is vulnerable to XML External Entity (XXE) Attack

XML External Entity (XXE) AttackCVE-2023-38693 Published Mar 17, 2025

98

Critical Risk

This Affects:

JAVAlucee
0.0.1 - 5.3.7.58
Fixed in 5.3.7.59
5.3.8.132-RC - 5.3.12.0
Fixed in 5.3.12.1
5.4.0.65-RC - 5.4.3.1
Fixed in 5.4.3.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to XML External Entity (XXE) injection in its REST endpoint. An attacker can exploit this by submitting malicious XML data, potentially leading to arbitrary code execution, data exfiltration, or denial of service.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

lucee is vulnerable to XML External Entity (XXE) Attack in versions 0.0.1 - 5.3.7.58, 5.3.8.132-RC - 5.3.12.0 and 5.4.0.65-RC - 5.4.3.1.

How to fix this

Upgrade the org.lucee:lucee library to a patch version.