CVE-2024-53961

Published Dec 23, 2024

Last updated 16 days ago

Overview

Description
ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access files or directories that are outside of the restricted directory set by the application. This could lead to the disclosure of sensitive information or the manipulation of system data.
Source
psirt@adobe.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

psirt@adobe.com
CWE-22

Social media

Hype score
Not currently trending
  1. Adobe ColdFusion の深刻な脆弱性 CVE-2024-53961 が FIX:PoC も登場 https://t.co/7LLUQO8HvB Adobe ColdFusion の、パス・トラバーサルの脆弱性が FIX しました。文中には、PoC の存在が記載されていますが、Adobe のアドバイザリでは、それらしきものが見つかりませんでした。 なお、CISA… https://t.co/4w02OEgmKW

    @iototsecnews

    6 Jan 2025

    96 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. به تازگی آسیب پذیری جدیدی برای محصول ColdFusion منتشر است. این آسیب پذیری دارای کد شناسایی CVE-2024-53961 و از نوع path traversal می باشد نسخه های 2021 و 2023 مربوط به این محصول دارای این آسیب پذیری هستند. برای پیشگیری و مقابله با این تهدید به روز رسانی ارائه شده را اعمال نمایید

    @cybernetic_cy

    28 Dec 2024

    127 Impressions

    2 Retweets

    5 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2024-53961 (CVSS:7.4, HIGH) is Awaiting Analysis. ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Di..https://t.co/6JQoYXei2Q #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    28 Dec 2024

    4 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Adobe $ADBE has released an out-of-band security update to address a critical ColdFusion vulnerability (CVE-2024-53961) with proof-of-concept exploit code. This flaw could allow attackers to read arbitrary files on vulnerable servers. Users are advised to apply the patch… https:

    @bullishchart

    27 Dec 2024

    92 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2024-53961 (CVSS:7.4, HIGH) is Awaiting Analysis. ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Di..https://t.co/6JQoYXei2Q #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    27 Dec 2024

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. #Vulnerability #AdobeColdFusion PoC Exploit Emerges for Adobe ColdFusion CVE-2024-53961—Apply Security Updates Now https://t.co/q1P3CGeJDU

    @Komodosec

    27 Dec 2024

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. آسیب پذیری جدیدی برای محصول ColdFusion منتشر است. آسیب پذیری دارای کد شناسایی CVE-2024-53961 و از نوع path traversal می باشد. نسخه های 2021 و 2023 دارای این آسیب پذیری هستند. برای پیشگیری و مقابله با این تهدید به روز رسانی ارائه شده را اعمال نمایید https://t.co/Poz3aKYxT1 https:

    @AmirHossein_sec

    26 Dec 2024

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Top 5 Trending CVEs: 1 - CVE-2024-53961 2 - CVE-2024-9474 3 - CVE-2024-30085 4 - CVE-2024-45387 5 - CVE-2024-12744 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    26 Dec 2024

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 CVE-2024-53961: Grave vulnerabilidad en Adobe ColdFusion expone archivos sensibles https://t.co/SHJ3zgKpRh

    @tpx_Security

    25 Dec 2024

    195 Impressions

    2 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Adobe исправляет уязвимость в ColdFusion, для которой уже доступен эксплоит Компания Adobe предупредила о существовании proof-of-concept эксплоита для свежей уязвимости в ColdFusion (CVE-2024-53961) и выпустила внеплановые патчи. https://t.co/8MPBHfmkgF

    @XakepRU

    25 Dec 2024

    501 Impressions

    0 Retweets

    4 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  11. Adobe advierte de un error crítico en ColdFusion con código de explotación PoC https://t.co/gjc8Sckquq CVE-2024-53961 https://t.co/sC8chCMluW https://t.co/RsxdQwRPrf

    @elhackernet

    25 Dec 2024

    3847 Impressions

    10 Retweets

    27 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  12. Adobe released out-of-band security updates to address a critical ColdFusion vulnerability with proof-of-concept (PoC) exploit code. An advisory released Monday, the company says the flaw (tracked as CVE-2024-53961) is caused by a path traversal weakness. https://t.co/1DURrXt8T9

    @riskigy

    25 Dec 2024

    75 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Hackers exploit path traversal vulnerabilities to breach systems & steal data. Adobe's latest ColdFusion flaw (CVE-2024-53961) highlights the risks. Emergency patches are out. Prioritize securing your servers in 72 hours to stay protected. https://t.co/HmVO8TgR7Z

    @Shift6Security

    25 Dec 2024

    89 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Adobe warns of critical ColdFusion bug with PoC exploit code: https://t.co/dqf4thTNBp Adobe has issued emergency security updates for a critical ColdFusion vulnerability (CVE-2024-53961) affecting versions 2023 and 2021, caused by a path traversal weakness that allows attackers…

    @securityRSS

    25 Dec 2024

    77 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. Adobe ColdFusion Kritik Güvenlik Açığı: CVE-2024-53961 https://t.co/YMfNZbq9tf

    @cyberwebeyeos

    25 Dec 2024

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Top 5 Trending CVEs: 1 - CVE-2024-53961 2 - CVE-2024-30085 3 - CVE-2024-56375 4 - CVE-2024-30088 5 - CVE-2024-56337 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    25 Dec 2024

    128 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Adobe ColdFusionの脆弱性対策について(CVE-2024-53961) https://t.co/NT8bLuegpt

    @testshinotsuka

    25 Dec 2024

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 🚨Alert🚨CVE-2024-53961 : PoC Exploit Emerges-Severe Path Traversal Vulnerability in Adobe ColdFusion 📊 8.5m+ Services are found on https://t.co/ysWb28BTvF yearly. 🔗Hunter Link: https://t.co/yOoXxWIUwI 👇Query HUNTER :/product.name="Adobe ColdFusion" FOFA :… https://t.co/L5eh4L

    @HunterMapping

    25 Dec 2024

    4414 Impressions

    13 Retweets

    78 Likes

    33 Bookmarks

    1 Reply

    0 Quotes

  19. 𝐀𝐝𝐨𝐛𝐞 𝐏𝐚𝐭𝐜𝐡𝐞𝐬 𝐕𝐮𝐥𝐧𝐞𝐫𝐚𝐛𝐢𝐥𝐢𝐭𝐢𝐞𝐬 Adobe has issued out-of-band security patches for its ColdFusion app server after discovering a critical path traversal vulnerability (CVE-2024-53961). The vulnerability allows attackers to gain unauthorized access to… h

    @TechBuzzRecap

    25 Dec 2024

    84 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. 𝐀𝐝𝐨𝐛𝐞 𝐂𝐨𝐥𝐝𝐅𝐮𝐬𝐢𝐨𝐧: 𝐂𝐫𝐢𝐭𝐢𝐜𝐚𝐥 𝐕𝐮𝐥𝐧𝐞𝐫𝐚𝐛𝐢𝐥𝐢𝐭𝐢𝐞𝐬 𝐃𝐢𝐬𝐜𝐨𝐯𝐞𝐫𝐞𝐝 According to socradar, a critical vulnerability known as CVE-2024-53961 has been discovered in Adobe ColdFusion versions 2023 and 2021. This vulnerability allows attackers to… h

    @TechBuzzRecap

    24 Dec 2024

    74 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. Adobe ColdFusionの脆弱性対策について(CVE-2024-53961) #IPA (Dec 24) https://t.co/ye4kGuSEEr

    @foxbook

    24 Dec 2024

    283 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. 🚨 Critical Adobe ColdFusion Bug with PoC Exploit Code Discovered! 🚨 WIRE TOR - The Ethical Hacking Services Adobe has issued an out-of-band security update to address a critical vulnerability (CVE-2024-53961) in ColdFusion. This flaw is rated "Priority 1" due to its #hacker ht

    @WireTor

    24 Dec 2024

    82 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. Adobe ColdFusion Bug: When Path Traversal Takes a Detour to Chaos! Hot Take: Looks like Adobe’s ColdFusion is heating up in all the wrong ways. With a bug named CVE-2024-53961 lingering like an unwanted holiday gift, Adobe's out-of-band updates are like the fire extinguisher in

    @TheNimbleNerd

    24 Dec 2024

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. #Adobe is aware that #ColdFusion bug CVE-2024-53961 has a known PoC exploit code https://t.co/NdKJaP73VH #securityaffairs #hacking

    @securityaffairs

    24 Dec 2024

    546 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  25. The flaw, tracked as CVE-2024-53961, is a path traversal vulnerability is Adobe Coldfusion that could allow malicious actors to read arbitrary files on affected servers, potentially exposing sensitive data. #infosecurity #TechNews #cybersecu https://t.co/Xm6gr6m1zg

    @LHackingupdates

    24 Dec 2024

    50 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. Adobe ColdFusionの脆弱性対策について(CVE-2024-53961) | 情報セキュリティ | IPA 独立行政法人 情報処理推進機構 https://t.co/HBQuEce36M

    @ntsuji

    24 Dec 2024

    2549 Impressions

    1 Retweet

    8 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  27. 🚨 Adobe ColdFusion Vulnerability (CVE-2024-53961) 🔹 Critical flaw with exploitation risks 🔹 Potential for data breaches 🔹 Apply updates immediately! 🔍 Full details: https://t.co/lKpMgBRkdL #CyberSecurity #VulnerabilityManagement #PatchNow #AdobeColdFusion https://t.co/TGGe9

    @socradar

    24 Dec 2024

    183 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  28. CVE-2024-53961: Path Traversal in Adobe ColdFusion, 7.4 rating❗️ Fresh vuln allows attackers to read arbitrary files on the server, including confidential information. Search at https://t.co/hv7QKSqxTR: 👉 Link: https://t.co/b1K25FMegT #cybersecurity #vulnerability_map https:/

    @Netlas_io

    24 Dec 2024

    484 Impressions

    2 Retweets

    10 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  29. CVE Alert: CVE-2024-53961 - https://t.co/n0DiiYkLWc #OSINT #ThreatIntel #CyberSecurity #cve_2024_53961

    @RedPacketSec

    24 Dec 2024

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. Adobe ColdFusionの脆弱性対策について(CVE-2024-53961) https://t.co/foJXCyg2oe

    @ICATalerts

    24 Dec 2024

    4533 Impressions

    8 Retweets

    8 Likes

    1 Bookmark

    0 Replies

    1 Quote

  31. IPA 重要 | Adobe ColdFusionの脆弱性対策について(CVE-2024-53961) https://t.co/Jk50Y77Mtv #itsec_jp

    @itsec_jp

    24 Dec 2024

    67 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. 🔨Apache Tomcatの重大なRCE脆弱性が修正される:CVE-2024-56337 ⚠️AdobeがColdFusionの重大な脆弱性について警告、PoCも存在:CVE-2024-53961 〜サイバーアラート 12月24日〜 https://t.co/t4vCGSKMQl #セキュリティ #インテリジェンス #OSINT

    @MachinaRecord

    24 Dec 2024

    146 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  33. PoC Exploit Emerges for Adobe ColdFusion CVE-2024-53961—Apply Security Updates Now Urgent security update for Adobe ColdFusion: CVE-2024-53961. Take action now to safeguard your data from potential exploitation and file access https://t.co/Mo8aoEeXR0

    @the_yellow_fall

    24 Dec 2024

    45 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  34. 🚨 Critical Adobe ColdFusion Vulnerability Alert (CVE-2024-53961) 🚨 Adobe has issued urgent security patches for a critical path traversal flaw in ColdFusion (versions 2023 & 2021) that could allow arbitrary file access. The company stresses updating within 72 hours due to…

    @arunpratap786

    23 Dec 2024

    107 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. CVE-2024-53961 ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that … https://t.co/XNZcjZeVu8

    @CVEnew

    23 Dec 2024

    749 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations