Description
In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid.
Remediation
References
Related Vulnerabilities
GlassFish Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-3250)
WordPress Plugin Photospace Gallery Cross-Site Scripting (2.3.5)
WordPress Plugin Advanced Custom Fields (ACF) Information Disclosure (6.0.2)
Dolibarr Incorrect Default Permissions Vulnerability (CVE-2020-13240)
Magento Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-3458)