Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2021-32700 Details

Description

Ballerina is an open source programming language and platform for cloud application programmers. Ballerina versions 1.2.x and SL releases up to alpha 3 have a potential for a supply chain attack via MiTM against users. Http connections did not make use of TLS and certificate checking was ignored. The vulnerability allows an attacker to substitute or modify packages retrieved from BC thus allowing to inject malicious code into ballerina executables. This has been patched in Ballerina 1.2.14 and Ballerina SwanLake alpha4.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-306Missing Authentication for Critical Function[email protected]

Affected Products

ProductVersions
ballerina ballerina
< 1.2.14

CPE

  • cpe:2.3:a:ballerina:ballerina:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
ballerina swan lake
alpha1
alpha2
alpha3

CPE

  • cpe:2.3:a:ballerina:swan_lake:alpha1:*:*:*:*:*:*:*
  • cpe:2.3:a:ballerina:swan_lake:alpha2:*:*:*:*:*:*:*
  • cpe:2.3:a:ballerina:swan_lake:alpha3:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2021-32700
NVD Published Date:
Jun 22, 2021
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2021-32700 Details - Not Deferred