CVE-2024-20767
Adobe ColdFusion Improper Access Control Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
5Exploited in Wild
YesDecision
Descriptions
ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could lead to arbitrary file system read. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access to sensitive files and perform arbitrary file system write. Exploitation of this issue does not require user interaction.
Las versiones 2023.6, 2021.12 y anteriores de ColdFusion se ven afectadas por una vulnerabilidad de control de acceso inadecuado que podría provocar una lectura arbitraria del sistema de archivos. Un atacante podría aprovechar esta vulnerabilidad para eludir las medidas de seguridad y obtener acceso no autorizado a archivos confidenciales y realizar escrituras arbitrarias en el sistema de archivos. La explotación de este problema no requiere la interacción del usuario.
ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel be exposed to the internet.
Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel.
CVSS Scores
SSVC
- Decision:Act
Timeline
- 2023-12-04 CVE Reserved
- 2024-03-18 CVE Published
- 2024-03-26 First Exploit
- 2024-12-16 Exploited in Wild
- 2024-12-17 CVE Updated
- 2025-01-06 KEV Due Date
- 2025-03-18 EPSS Updated
CWE
- CWE-284: Improper Access Control
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
https://jeva.cc/2973.html |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/180607 | 2024-08-31 | |
https://github.com/yoryio/CVE-2024-20767 | 2024-03-26 | |
https://github.com/Chocapikk/CVE-2024-20767 | 2024-03-26 | |
https://github.com/Praison001/CVE-2024-20767-Adobe-ColdFusion | 2024-04-01 | |
https://github.com/m-cetin/CVE-2024-20767 | 2024-03-26 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://helpx.adobe.com/security/products/coldfusion/apsb24-14.html | 2024-03-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | ColdFusion Search vendor "Adobe" for product "ColdFusion" | <= 2021.12 Search vendor "Adobe" for product "ColdFusion" and version " <= 2021.12" | en |
Affected
|