CVE-2023-29300: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
Other sources
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Discontinue use of Adobe ColdFusion if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the vulnerability ID for Adobe ColdFusion?
The vulnerability ID for Adobe ColdFusion is CVE-2023-29300.
What is the severity of CVE-2023-29300?
The severity of CVE-2023-29300 is critical.
Which versions of Adobe ColdFusion are affected by CVE-2023-29300?
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier), and 2023.0.0.330468 (and earlier) are affected by CVE-2023-29300.
What is the impact of the vulnerability CVE-2023-29300?
The vulnerability CVE-2023-29300 could result in arbitrary code execution.
How can I fix the vulnerability CVE-2023-29300?
To fix the vulnerability CVE-2023-29300, update Adobe ColdFusion to a version that is not affected by the vulnerability.