First published: Mon Dec 23 2024(Updated: )
ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access files or directories that are outside of the restricted directory set by the application. This could lead to the disclosure of sensitive information or the manipulation of system data.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | >2021.17 | |
Adobe ColdFusion | =2021 | |
Adobe ColdFusion | =2021-update1 | |
Adobe ColdFusion | =2021-update10 | |
Adobe ColdFusion | =2021-update11 | |
Adobe ColdFusion | =2021-update12 | |
Adobe ColdFusion | =2021-update13 | |
Adobe ColdFusion | =2021-update14 | |
Adobe ColdFusion | =2021-update15 | |
Adobe ColdFusion | =2021-update16 | |
Adobe ColdFusion | =2021-update17 | |
Adobe ColdFusion | =2021-update2 | |
Adobe ColdFusion | =2021-update3 | |
Adobe ColdFusion | =2021-update4 | |
Adobe ColdFusion | =2021-update5 | |
Adobe ColdFusion | =2021-update6 | |
Adobe ColdFusion | =2021-update7 | |
Adobe ColdFusion | =2021-update8 | |
Adobe ColdFusion | =2021-update9 | |
Adobe ColdFusion | =2023 | |
Adobe ColdFusion | =2023-update1 | |
Adobe ColdFusion | =2023-update10 | |
Adobe ColdFusion | =2023-update11 | |
Adobe ColdFusion | =2023-update2 | |
Adobe ColdFusion | =2023-update3 | |
Adobe ColdFusion | =2023-update4 | |
Adobe ColdFusion | =2023-update5 | |
Adobe ColdFusion | =2023-update6 | |
Adobe ColdFusion | =2023-update7 | |
Adobe ColdFusion | =2023-update8 | |
Adobe ColdFusion | =2023-update9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-53961 is classified as a critical vulnerability due to its potential for arbitrary file system read.
To fix CVE-2024-53961, update to the latest version of Adobe ColdFusion that addresses this vulnerability.
ColdFusion versions 2023.11, 2021.17, and earlier are affected by CVE-2024-53961.
CVE-2024-53961 is an Improper Limitation of a Pathname to a Restricted Directory, commonly known as a Path Traversal vulnerability.
Exploitation of CVE-2024-53961 could allow an attacker to read arbitrary files or directories on the system.