Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans. SPEL Expression does not have security restrictions, which will cause attackers to execute arbitrary commands remotely (RCE).
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: crafter

Published: 2021-12-02T15:40:54.175089Z

Updated: 2024-09-16T22:02:38.381Z

Reserved: 2021-01-08T00:00:00

Link: CVE-2021-23258

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-12-02T16:15:07.437

Modified: 2021-12-03T18:17:36.290

Link: CVE-2021-23258

cve-icon Redhat

No data.