« Volver al listado

CVE-2023-26361

Estado: ModificadaMedia (4.9)—

Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in Arbitrary file system read. Exploitation of this issue does not require user interaction, but does require administrator privileges.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-26361",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-26361",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-03-05T18:39:54.607839Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@adobe.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@adobe.com",
      "affectedData": [
        {
          "vendor": "Adobe",
          "product": "ColdFusion",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "CF2018U15, CF2021U5"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "None"
            }
          ]
        }
      ]
    }
  ],
  "published": "2023-03-23T20:15:15.373",
  "references": [
    {
      "url": "https://helpx.adobe.com/security/products/coldfusion/apsb23-25.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://helpx.adobe.com/security/products/coldfusion/apsb23-25.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@adobe.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in Arbitrary file system read. Exploitation of this issue does not require user interaction, but does require administrator privileges."
    }
  ],
  "lastModified": "2026-06-17T05:43:10.487",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2018:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B54B2B0-B1E1-4B4E-A529-D0BD3B5DEEF3"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2018:update1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EDB126BF-E09D-4E58-A39F-1190407D1CAB"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2018:update10:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8DDD85DF-69A0-476F-8365-CD67C75CF0CE"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2018:update11:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23F63675-7817-4AF0-A7DB-5E35EDABF04E"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2018:update12:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3E3BF53E-2C0D-4F79-8B62-4C2A50CB5F52"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2018:update13:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C26BF72C-E991-4170-B68B-09B20B6C0679"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2018:update14:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "25B4B4F2-318F-4046-ADE5-E9DD64F83FD9"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2018:update15:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "831E8D69-62E9-4778-8CC5-D6D45CF5AB6F"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2018:update2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "59649177-81EE-43C3-BFA5-E56E65B486DF"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2018:update3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "453B96ED-738A-4642-B461-C5216CF45CA3"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2018:update4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "58D32489-627B-4E49-9329-8A3B8F8E4903"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2018:update5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D5860E1-D293-48FE-9796-058B78B2D571"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2018:update6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F9336CC-E38F-4BCB-83CD-805EC7FEF806"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2018:update7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "97964507-047A-4CC8-8D2B-0EA0C7F9BD50"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2018:update8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "82208628-F32A-4380-9B0F-DC8507E7701D"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2018:update9:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1563CE5E-A4F7-40A4-A050-BB96E332D8DD"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2021:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A94B406-C011-4673-8C2B-0DD94D46CC4C"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2021:update1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AFD05E3A-10F9-4C75-9710-BA46B66FF6E6"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2021:update2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D57C8681-AC68-47DF-A61E-B5C4B4A47663"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2021:update3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "75608383-B727-48D6-8FFA-D552A338A562"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2021:update4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7773DB68-414A-4BA9-960F-52471A784379"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2021:update5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B38B9E86-BCD5-4BCA-8FB7-EC55905184E6"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@adobe.com"
}