CISA Known Exploited Vulnerability (KEV)
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
January 8, 2024
January 29, 2024
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
Weakness Enumeration
CWE-ID | CWE Name |
---|---|
CWE-502 |
Deserialization of Untrusted Data |