CVE-2021-28170 (Medium) detected in javax.el-3.0.0.jar #608
Labels
infrastructure
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2021-28170 - Medium Severity Vulnerability
Vulnerable Library - javax.el-3.0.0.jar
Java.net - The Source for Java Technology Collaboration
Library home page: http://glassfish.org
Path to dependency file: /build.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.glassfish/javax.el/3.0.0/dd532526e7c8de48e40419e6af1183658a973379/javax.el-3.0.0.jar
Dependency Hierarchy:
Found in base branch: main
Vulnerability Details
In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid.
Publish Date: 2021-05-26
URL: CVE-2021-28170
CVSS 3 Score Details (5.3)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://www.cve.org/CVERecord?id=CVE-2021-28170
Release Date: 2021-05-26
Fix Resolution: org.glassfish:jakarta.el:3.0.4, com.sun.el:el-ri:3.0.4
The text was updated successfully, but these errors were encountered: