Description
In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid.
Remediation
References
Related Vulnerabilities
Envoy Wrong DOWNSTREAM_REMOTE_ADDRESS logged Issue (CVE-2020-35470)
WordPress Plugin EWWW Image Optimizer Denial of Service (6.0.1)
WordPress Plugin WPtouch Cross-Site Request Forgery (1.9.31)
Moodle CVE-2021-32473 Vulnerability (CVE-2021-32473)
VMware directory traversal and privilege escalation vulnerabilities