ColdFusion version 2021 update 1 (and earlier) and...
High severity
Unreviewed
Published
Sep 7, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Sep 7, 2023
Published to the GitHub Advisory Database
Sep 7, 2023
Last updated
Apr 4, 2024
ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an Use of Inherently Dangerous Function vulnerability that can lead to a security feature bypass??. An authenticated attacker could leverage this vulnerability to access and manipulate arbitrary data on the environment.
References