CVE-2024-20767
Coldfusion 2023/2021 Pre-Auth monitor uuid leak lead to arbitrary file read/write
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could lead to arbitrary file system read. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access to sensitive files and perform arbitrary file system write. Exploitation of this issue does not require user interaction.
Las versiones 2023.6, 2021.12 y anteriores de ColdFusion se ven afectadas por una vulnerabilidad de control de acceso inadecuado que podría provocar una lectura arbitraria del sistema de archivos. Un atacante podría aprovechar esta vulnerabilidad para eludir las medidas de seguridad y obtener acceso no autorizado a archivos confidenciales y realizar escrituras arbitrarias en el sistema de archivos. La explotación de este problema no requiere la interacción del usuario.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-12-04 CVE Reserved
- 2024-03-18 CVE Published
- 2024-03-26 First Exploit
- 2024-08-29 EPSS Updated
- 2024-09-13 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-284: Improper Access Control
CAPEC
References (5)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/yoryio/CVE-2024-20767 | 2024-03-26 | |
https://github.com/Chocapikk/CVE-2024-20767 | 2024-03-26 | |
https://github.com/Praison001/CVE-2024-20767-Adobe-ColdFusion | 2024-04-01 | |
https://github.com/m-cetin/CVE-2024-20767 | 2024-03-26 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://helpx.adobe.com/security/products/coldfusion/apsb24-14.html | 2024-03-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | ColdFusion Search vendor "Adobe" for product "ColdFusion" | <= 2021.12 Search vendor "Adobe" for product "ColdFusion" and version " <= 2021.12" | en |
Affected
|