Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
References
Link | Resource |
---|---|
https://helpx.adobe.com/security/products/coldfusion/apsb23-52.html | Release Notes Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
23 Nov 2023, 03:38
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-11-17 14:15
Updated : 2024-02-05 00:22
NVD link : CVE-2023-44353
Mitre link : CVE-2023-44353
CVE.ORG link : CVE-2023-44353
JSON object : View
Products Affected
adobe
- coldfusion
CWE
CWE-502
Deserialization of Untrusted Data