PT-2024-4220 · Adobe · Coldfusion

Published

2024-06-11

·

Updated

2025-01-13

·

CVE-2024-34112

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions ColdFusion versions 2023u7, 2021u13 and earlier
Description The issue is related to improper access control, which could result in arbitrary file system read. An attacker could exploit this to gain unauthorized access to sensitive files or data without requiring user interaction. This allows a remote attacker to obtain unauthorized access to protected information.
Recommendations For ColdFusion versions 2023u7 and earlier, update to a version that addresses the improper access control issue. For ColdFusion version 2021u13 and earlier, update to a version that addresses the improper access control issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2024-04706
CVE-2024-34112

Affected Products

Coldfusion