CVE-2022-42341: Adobe ColdFusion Improper Restriction of XML External Entity Reference Arbitrary file system read
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-42341?
CVE-2022-42341 is a vulnerability in Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) that allows arbitrary file system read due to an improper restriction of XML external entity reference (XXE).
How severe is CVE-2022-42341?
CVE-2022-42341 has a severity rating of 7.5 (high).
Which versions of Adobe ColdFusion are affected by CVE-2022-42341?
Adobe ColdFusion versions 2018 (all updates), 2021 (all updates), Update 14 (and earlier), and Update 4 (and earlier) are affected by CVE-2022-42341.
How can CVE-2022-42341 be exploited?
Exploitation of CVE-2022-42341 does not require user interaction.
Where can I find more information about CVE-2022-42341?
You can find more information about CVE-2022-42341 on the Adobe Security Bulletin APSB22-44.