CVE-2021-28170 | Jakarta Expression Language up to 3.0.3 ELParserTokenManager input validation (GHSL-2020-021 / Nessus ID 240506)
A vulnerability was found in Jakarta Expression Language up to 3.0.3. It has been declared as critical. Affected by this vulnerability is the function ELParserTokenManager. The manipulation leads to improper input validation.
This vulnerability is known as CVE-2021-28170. The attack can only be done within the local network. There is no exploit available.