First published: Fri Oct 14 2022(Updated: )
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | =2018 | |
Adobe ColdFusion | =2018-update1 | |
Adobe ColdFusion | =2018-update10 | |
Adobe ColdFusion | =2018-update11 | |
Adobe ColdFusion | =2018-update12 | |
Adobe ColdFusion | =2018-update13 | |
Adobe ColdFusion | =2018-update14 | |
Adobe ColdFusion | =2018-update2 | |
Adobe ColdFusion | =2018-update3 | |
Adobe ColdFusion | =2018-update4 | |
Adobe ColdFusion | =2018-update5 | |
Adobe ColdFusion | =2018-update6 | |
Adobe ColdFusion | =2018-update7 | |
Adobe ColdFusion | =2018-update8 | |
Adobe ColdFusion | =2018-update9 | |
Adobe ColdFusion | =2021 | |
Adobe ColdFusion | =2021-update1 | |
Adobe ColdFusion | =2021-update2 | |
Adobe ColdFusion | =2021-update3 | |
Adobe ColdFusion | =2021-update4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42341 is a vulnerability in Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) that allows arbitrary file system read due to an improper restriction of XML external entity reference (XXE).
CVE-2022-42341 has a severity rating of 7.5 (high).
Adobe ColdFusion versions 2018 (all updates), 2021 (all updates), Update 14 (and earlier), and Update 4 (and earlier) are affected by CVE-2022-42341.
Exploitation of CVE-2022-42341 does not require user interaction.
You can find more information about CVE-2022-42341 on the Adobe Security Bulletin APSB22-44.