CVE-2023-29300 is a critical deserialization of untrusted data vulnerability affecting Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier), and 2023.0.0.330468 (and earlier). This flaw allows for arbitrary code execution without user interaction, carrying a CVSS score of 9.8 (Critical). It is actively exploited in the wild, including in known ransomware campaigns, and has high exploitability with readily available Nuclei templates. The vulnerability has garnered significant community discussion and media coverage, highlighting its severe risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2018CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2018:-:*:*:*:*:*:* | ||
2018CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2018:update1:*:*:*:*:*:* | ||
2018CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2018:update10:*:*:*:*:*:* | ||
2018CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2018:update11:*:*:*:*:*:* | ||
2018CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2018:update12:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.