CVE-2024-20767
Adobe ColdFusion
Published 18 Mar 2024 · updated 17 Jun 2026 · Analyzed
7.4 High · CVSS 3.1, adobe.com
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 16 Dec 2024, with a remediation deadline of 6 Jan 2025 for US federal agencies.
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel be exposed to the internet.
References
- helpx.adobe.com/security/products/coldfusion/apsb24-14.html · Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-20767 · Third Party Advisory, US Government Resource