CVE-2021-28170

CVE-2021-28170

Vendor The Eclipse Foundation
Product Jakarta Expression Language Implementation
Weakness CWE-20 · Input validation
Published May 26, 2021
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid.

Key dates

02Disclosure timeline

May 26, 2021 CVE published
August 3, 2024 Record updated