SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-34112

ColdFusion versions 2023u7, 2021u13 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read.

HIGH 7.5EPSS 23.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 23.7%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

ColdFusion versions 2023u7, 2021u13 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could exploit this vulnerability to gain unauthorized access to sensitive files or data. Exploitation of this issue does not require user interaction.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
23.70% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-284
Affected
adobe/coldfusion
Source
psirt@adobe.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.