HIGH

CVE-2024-20767

Adobe Coldfusion 2024-03-18 CVSS v3.1
CVSS
7.4
KEV

Description

ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel be exposed to the internet.

Summary dbcve.org

ColdFusion versions 2023.6, 2021.12 and earlier contain an Improper Access Control vulnerability that allows unauthenticated attackers to read arbitrary files from the file system. Exploitation requires the admin panel to be internet-exposed but does not require any user interaction.

Mitigation

Immediately restrict access to the ColdFusion admin panel so it is not accessible from the internet; only allow access from trusted internal IP ranges. Consider upgrading to the latest patched ColdFusion versions.

Weakness (CWE)

CWE-284 Improper Access Control

EPSS Score

98.51%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE