CVE-2023-29298: Adobe ColdFusion Improper Access Control Vulnerability
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.
Other sources
Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Discontinue use of Adobe ColdFusion if mitigations are unavailable.
- Operational
Identify all Adobe ColdFusion installations and inventory those running versions 2018u16 (and earlier), 2021u6 (and earlier), or 2023.0.0.330468 (and earlier).
Event History
Frequently Asked Questions
What is CVE-2023-29298?
CVE-2023-29298 is an Improper Access Control vulnerability in Adobe ColdFusion.
Which versions of Adobe ColdFusion are affected by CVE-2023-29298?
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier), and 2023.0.0.330468 (and earlier) are affected.
What is the severity of CVE-2023-29298?
CVE-2023-29298 has a severity rating of 7, which is considered high.
How can this vulnerability be exploited?
An attacker could exploit this vulnerability to bypass security features and gain unauthorized access to the administration CFM and CFC endpoints.
Where can I find more information about CVE-2023-29298?
You can find more information about CVE-2023-29298 at the following link: [Adobe Security Bulletin APSB23-40](https://helpx.adobe.com/security/products/coldfusion/apsb23-40.html).