VDB

CVE-2024-34112

CVE-2024-34112 PUBLISHED CVSS 7.5 HIGH

Adobe has released security updates for ColdFusion versions 2023 and 2021. These updates resolve important vulnerabilities that could lead to arbitrary file system read and security feature bypass. Vulnerability: Improper Access Control (CWE-284) Impact: Arbitrary file system read Severity: Important CVSS: 7.5 CWE: CWE-284

EPSS 23.70% · 97.6th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
23.70%
97.6th percentile

Affected Products

VendorProductVersions
AdobeColdFusion 2021*, *
AdobeColdFusion 2023*, *
AdobeProduct*, *

Timeline

  • Jun 11, 2024 CVE Published
  • Jun 14, 2024 EPSS Score
  • Jul 7, 2024 EPSS Score
  • Aug 2, 2024 CVE Updated
  • Aug 22, 2024 EPSS Score
  • Sep 14, 2024 EPSS Score
  • Oct 4, 2024 Coalition ESS Score
  • Oct 7, 2024 EPSS Score
  • Oct 30, 2024 EPSS Score
  • Dec 15, 2024 EPSS Score
  • Jan 7, 2025 EPSS Score
  • Jan 14, 2025 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›