CVE-2024-53961: ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access files or directories that are outside of the restricted directory set by the application. This could lead to the disclosure of sensitive information or the manipulation of system data. Exploitation of this issue requires the admin panel be exposed to the internet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-53961?
CVE-2024-53961 is classified as a critical vulnerability due to its potential for arbitrary file system read.
How do I fix CVE-2024-53961?
To fix CVE-2024-53961, update to the latest version of Adobe ColdFusion that addresses this vulnerability.
Which versions of ColdFusion are affected by CVE-2024-53961?
ColdFusion versions 2023.11, 2021.17, and earlier are affected by CVE-2024-53961.
What type of vulnerability is CVE-2024-53961?
CVE-2024-53961 is an Improper Limitation of a Pathname to a Restricted Directory, commonly known as a Path Traversal vulnerability.
What could an attacker achieve by exploiting CVE-2024-53961?
Exploitation of CVE-2024-53961 could allow an attacker to read arbitrary files or directories on the system.