CVE-2022-42340: Adobe ColdFusion Improper Input Validation Arbitrary file system read
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-42340?
CVE-2022-42340 is a vulnerability in Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) that allows arbitrary file system read.
How severe is CVE-2022-42340?
CVE-2022-42340 has a severity rating of 7.5, which is considered high.
Which versions of Adobe ColdFusion are affected by CVE-2022-42340?
Adobe ColdFusion versions 2018, 2018-update1, 2018-update2, 2018-update3, 2018-update4, 2018-update5, 2018-update6, 2018-update7, 2018-update8, 2018-update9, 2018-update10, 2018-update11, 2018-update12, 2018-update13, 2018-update14, 2021, 2021-update1, 2021-update2, 2021-update3, and 2021-update4 are affected by CVE-2022-42340.
How can I fix CVE-2022-42340?
To fix CVE-2022-42340, update your Adobe ColdFusion installation to a version that is not affected by the vulnerability, as recommended by Adobe.
Where can I find more information about CVE-2022-42340?
You can find more information about CVE-2022-42340 on the Adobe security advisory page: https://helpx.adobe.com/security/products/coldfusion/apsb22-44.html