Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
History

Mon, 16 Sep 2024 13:15:00 +0000

Type Values Removed Values Added
Title ColdFusion Mass Assignment Vulnerability via argumentCollection values passed to Remote CFC Methods ColdFusion | Deserialization of Untrusted Data (CWE-502)

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published: 2023-11-17T13:31:30.360Z

Updated: 2024-09-16T12:57:22.438Z

Reserved: 2023-09-28T16:25:40.451Z

Link: CVE-2023-44350

cve-icon Vulnrichment

Updated: 2024-08-02T20:07:32.158Z

cve-icon NVD

Status : Analyzed

Published: 2023-11-17T14:15:21.293

Modified: 2023-11-23T03:39:25.393

Link: CVE-2023-44350

cve-icon Redhat

No data.