{"id":"CVE-2021-1627","details":"MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. This affects: Mule 3.8.x,3.9.x,4.x runtime released before February 2, 2021.","modified":"2026-04-11T23:13:58.995171Z","published":"2021-03-26T17:15:12.640Z","references":[{"type":"ADVISORY","url":"https://help.salesforce.com/articleView?id=000357383&type=1&mode=1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mulesoft/mule","events":[{"introduced":"4afebcb3312f72de86bd0adae763d5e6f1510b11"},{"last_affected":"011a6c41704144456e89f90d47015b060ffc8ba4"}],"database_specific":{"source":"CPE_FIELD","extracted_events":[{"introduced":"3.8.0"},{"last_affected":"4.2.2"}],"cpe":"cpe:2.3:a:salesforce:mule:*:*:*:*:*:*:*:*"}}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-1627.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}