CVE-2023-26361
Published on: Not Yet Published
Last Modified on: 03/28/2023 01:02:00 PM UTC
Certain versions of Coldfusion from Adobe contain the following vulnerability:
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in Arbitrary file system read. Exploitation of this issue does not require user interaction, but does require administrator privileges.
- CVE-2023-26361 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Adobe - ColdFusion version <= CF2018U15, CF2021U5
- Affected Vendor/Software:
Adobe - ColdFusion version <= None
- Affected Vendor/Software:
Adobe - ColdFusion version <= None
- Affected Vendor/Software:
Adobe - ColdFusion version <= None
CVSS3 Score: 4.9 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | HIGH | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Adobe Security Bulletin | helpx.adobe.com text/html |
![]() |
Related QID Numbers
- 378080 Adobe ColdFusion Multiple Vulnerabilities (APSB23-25)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Adobe | Coldfusion | 2018 | - | All | All |
Application | Adobe | Coldfusion | 2018 | update1 | All | All |
Application | Adobe | Coldfusion | 2018 | update10 | All | All |
Application | Adobe | Coldfusion | 2018 | update11 | All | All |
Application | Adobe | Coldfusion | 2018 | update12 | All | All |
Application | Adobe | Coldfusion | 2018 | update13 | All | All |
Application | Adobe | Coldfusion | 2018 | update14 | All | All |
Application | Adobe | Coldfusion | 2018 | update15 | All | All |
Application | Adobe | Coldfusion | 2018 | update2 | All | All |
Application | Adobe | Coldfusion | 2018 | update3 | All | All |
Application | Adobe | Coldfusion | 2018 | update4 | All | All |
Application | Adobe | Coldfusion | 2018 | update5 | All | All |
Application | Adobe | Coldfusion | 2018 | update6 | All | All |
Application | Adobe | Coldfusion | 2018 | update7 | All | All |
Application | Adobe | Coldfusion | 2018 | update8 | All | All |
Application | Adobe | Coldfusion | 2018 | update9 | All | All |
Application | Adobe | Coldfusion | 2021 | - | All | All |
Application | Adobe | Coldfusion | 2021 | update1 | All | All |
Application | Adobe | Coldfusion | 2021 | update2 | All | All |
Application | Adobe | Coldfusion | 2021 | update3 | All | All |
Application | Adobe | Coldfusion | 2021 | update4 | All | All |
Application | Adobe | Coldfusion | 2021 | update5 | All | All |
- cpe:2.3:a:adobe:coldfusion:2018:-:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update1:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update10:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update11:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update12:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update13:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update14:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update15:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update2:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update3:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update4:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update5:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update6:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update7:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update8:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2018:update9:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2021:-:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2021:update1:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2021:update2:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2021:update3:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2021:update4:*:*:*:*:*:*:
- cpe:2.3:a:adobe:coldfusion:2021:update5:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
Adobe ColdFusion directory traversal | CVE-2023-26361 - redpacketsecurity.com/adobe-coldfusi… #CVE #Vulnerability #OSINT #ThreatIntel #Cyber | 2023-03-17 10:07:26 |
![]() |
CVE-2023-26361 : Adobe ColdFusion versions 2018 Update 15 and earlier and 2021 Update 5 and earlier are affecte… twitter.com/i/web/status/1… | 2023-03-23 20:09:08 |
![]() |
MS-ISAC CYBERSECURITY ADVISORY - Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution - PATCH NOW | 2023-03-15 12:44:55 |
![]() |
CVE-2023-26361 | 2023-03-23 20:38:28 |