CVE-2024-20767 is an Improper Access Control vulnerability affecting Adobe ColdFusion versions 2023.6, 2021.12, and earlier, allowing for arbitrary file system reads without user interaction. With a CVSS score of 7.4 (HIGH), it presents a significant risk, enabling attackers to access or modify restricted files if the admin panel is exposed to the internet. This vulnerability is actively exploited in the wild, with readily available exploit code in Metasploit, Nuclei, and ExploitDB, and has garnered substantial community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 2021.12CPE match | cpe:2.3:a:adobe:coldfusion:*:*:*:*:*:*:*:* | ||
2021CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2021:-:*:*:*:*:*:* | ||
2021CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2021:update1:*:*:*:*:*:* | ||
2021CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2021:update10:*:*:*:*:*:* | ||
2021CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2021:update11:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.