First published: Wed Jul 12 2023(Updated: )
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.
Credit: psirt@adobe.com psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | =2018 | |
Adobe ColdFusion | =2018-update1 | |
Adobe ColdFusion | =2018-update2 | |
Adobe ColdFusion | =2018-update3 | |
Adobe ColdFusion | =2018-update4 | |
Adobe ColdFusion | =2018-update5 | |
Adobe ColdFusion | =2018-update6 | |
Adobe ColdFusion | =2018-update7 | |
Adobe ColdFusion | =2018-update8 | |
Adobe ColdFusion | =2018-update9 | |
Adobe ColdFusion | =2018-update10 | |
Adobe ColdFusion | =2021 | |
Adobe ColdFusion | =2021-update1 | |
Adobe ColdFusion | =2021-update2 | |
Adobe ColdFusion | =2021-update3 | |
Adobe ColdFusion | =2018-update13 | |
Adobe ColdFusion | =2018-update12 | |
Adobe ColdFusion | =2018-update11 | |
Adobe ColdFusion | =2021-update4 | |
Adobe ColdFusion | =2018-update14 | |
Adobe ColdFusion | =2021-update5 | |
Adobe ColdFusion | =2018-update15 | |
Adobe ColdFusion | =2018-update16 | |
Adobe ColdFusion | =2021-update6 | |
Adobe ColdFusion | >=2023<=2023.0.0.330468 | |
Adobe ColdFusion | ||
>=2023<=2023.0.0.330468 | ||
=2018 | ||
=2018-update1 | ||
=2018-update10 | ||
=2018-update11 | ||
=2018-update12 | ||
=2018-update13 | ||
=2018-update14 | ||
=2018-update15 | ||
=2018-update16 | ||
=2018-update2 | ||
=2018-update3 | ||
=2018-update4 | ||
=2018-update5 | ||
=2018-update6 | ||
=2018-update7 | ||
=2018-update8 | ||
=2018-update9 | ||
=2021 | ||
=2021-update1 | ||
=2021-update2 | ||
=2021-update3 | ||
=2021-update4 | ||
=2021-update5 | ||
=2021-update6 |
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-29298 is an Improper Access Control vulnerability in Adobe ColdFusion.
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier), and 2023.0.0.330468 (and earlier) are affected.
CVE-2023-29298 has a severity rating of 7, which is considered high.
An attacker could exploit this vulnerability to bypass security features and gain unauthorized access to the administration CFM and CFC endpoints.
You can find more information about CVE-2023-29298 at the following link: [Adobe Security Bulletin APSB23-40](https://helpx.adobe.com/security/products/coldfusion/apsb23-40.html).