VDB
CVE-2024-34112
CVE-2024-34112
PUBLISHED
CVSS 7.5 HIGH
Adobe has released security updates for ColdFusion versions 2023 and 2021. These updates resolve important vulnerabilities that could lead to arbitrary file system read and security feature bypass. Vulnerability: Improper Access Control (CWE-284) Impact: Arbitrary file system read Severity: Important CVSS: 7.5 CWE: CWE-284
EPSS 23.70% · 97.6th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
23.70%
97.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | ColdFusion 2021 | *, * |
| Adobe | ColdFusion 2023 | *, * |
| Adobe | Product | *, * |
Timeline
- Jun 11, 2024 CVE Published
- Jun 14, 2024 EPSS Score
- Jul 7, 2024 EPSS Score
- Aug 2, 2024 CVE Updated
- Aug 22, 2024 EPSS Score
- Sep 14, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 7, 2024 EPSS Score
- Oct 30, 2024 EPSS Score
- Dec 15, 2024 EPSS Score
- Jan 7, 2025 EPSS Score
- Jan 14, 2025 PoC Published