漏洞描述
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
blog.projectdiscovery.iohttps://blog.projectdiscovery.io/adobe-coldfusion-rce/↗helpx.adobe.comhttps://helpx.adobe.com/security/products/coldfusion/apsb23-40.html↗github.comhttps://github.com/Ostorlab/KEV↗github.comhttps://github.com/Threekiii/Vulhub-Reproduce↗github.comhttps://github.com/XRSec/AWVS-Update↗