CVE-2024-20767
Description
ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel be exposed to the internet.
Summary dbcve.org
ColdFusion versions 2023.6, 2021.12 and earlier contain an Improper Access Control vulnerability that allows unauthenticated attackers to read arbitrary files from the file system. Exploitation requires the admin panel to be internet-exposed but does not require any user interaction.
Mitigation
Immediately restrict access to the ColdFusion admin panel so it is not accessible from the internet; only allow access from trusted internal IP ranges. Consider upgrading to the latest patched ColdFusion versions.