CVE-2025-54234: ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918)
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to limited file system read. A high-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54234?
CVE-2025-54234 has been rated as a high-severity vulnerability due to its potential for exploitation by high-privilege authenticated attackers.
How do I fix CVE-2025-54234?
To mitigate CVE-2025-54234, it is recommended to upgrade to the latest version of Adobe ColdFusion that addresses the SSRF vulnerability.
What versions of Adobe ColdFusion are affected by CVE-2025-54234?
CVE-2025-54234 affects Adobe ColdFusion versions 2025.1, 2023.13, 2021.19, and earlier.
What type of vulnerability is CVE-2025-54234?
CVE-2025-54234 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
Who can exploit CVE-2025-54234?
CVE-2025-54234 can be exploited by high-privilege authenticated attackers to make arbitrary requests.