Improper access control in ColdFusion - CVE-2023-38205

 

Improper access control in ColdFusion - CVE-2023-38205

Published: July 20, 2023


Vulnerability identifier: #VU78460
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-38205
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. A remote non-authenticated attacker can bypass implemented security restrictions and gain unauthorized access to the application.

Note, the vulnerability is being actively exploited in the wild.


Affected software

ColdFusion

How to mitigate CVE-2023-38205

Install updates from vendor's website.

ColdFusion - addressed in versions 2018 Update 19, 2021 Update 9, 2023 Update 3

External References

Related Security Bulletins