CVE-2023-38204Deserialization of Untrusted Data in Adobe Coldfusion

Severity
9.8CRITICALNVD
EPSS
74.7%
top 1.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 14

Description

Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5adobe/coldfusioncf2023U2
NVDadobe/coldfusion2018, 2021, 2023+2

🔴Vulnerability Details

3
CVEList
Bypass APSB23-41 (CVE-2023-38203) - Pre-Auth RCE ColdFusion 2021 Update 82023-09-14
GHSA
GHSA-77p2-6w3v-xjv8: Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deserialization of Untrusted Data vul2023-09-14
VulnCheck
Adobe ColdFusion Deserialization of Untrusted Data2023
CVE-2023-38204 — Deserialization of Untrusted Data | cvebase