S4E just found a medium-severity finding from self signed ssl certificate detection
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jul 8, 2024

CVE-2024-20767 Scanner

CVE-2024-20767 scanner - Arbitrary File Read vulnerability in Adobe ColdFusion

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2024-20767
7.4
CVSShigh
Exploitable remotely over the internet · no authentication required.

ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel be exposed to the internet.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
ColdFusionby Adobe
0
coldfusionby adobe
2023.0
coldfusionby adobe
2023.0
Updated Aug 22, 2026View on NVD →
Detail

Adobe ColdFusion is a commercial rapid web-application development platform created by Adobe. It is widely used by developers to build and deploy powerful web applications and services. Common users include web developers, IT professionals, and enterprises that require robust web application performance. ColdFusion simplifies the connection to databases, enhances coding productivity, and provides built-in support for various protocols and services. It is used in industries where dynamic web application functionalities are critical.

The vulnerability allows an attacker to read arbitrary files on the affected system. Exploitation does not require user interaction, making it particularly dangerous. The vulnerability is due to improper access control, which allows unauthorized access to sensitive files. If exploited, it can lead to significant information disclosure.

The vulnerability is found in the ColdFusion admin API endpoint /CFIDE/adminapi/_servermanager/servermanager.cfc with the method getHeartBeat. The endpoint improperly validates input, allowing directory traversal. This can be exploited by attackers to read sensitive files like /etc/passwd by manipulating the request parameters. The lack of sufficient access control checks is the root cause of this issue. Attackers can bypass security measures and gain unauthorized access to the file system.

Exploiting this vulnerability could result in unauthorized access to sensitive files, leading to information disclosure. Attackers could read configuration files, user data, and other critical information stored on the server. This can facilitate further attacks, including privilege escalation, and compromise the confidentiality of the data. Organizations could face data breaches and significant security incidents as a result.

By using the S4E platform, you can stay ahead of potential threats with our comprehensive Cyber Threat Exposure Management services. Our platform provides timely detection of vulnerabilities like the one described here, ensuring your systems are protected against unauthorized access and data breaches. Join our community to benefit from detailed security reports, continuous monitoring, and expert advice tailored to your unique security needs. Secure your digital assets today with S4E.

References:

Solution Advice
  • Apply the security patches provided by Adobe to fix the vulnerability.
  • Restrict access to the ColdFusion admin interface and API endpoints to trusted IP addresses only.
  • Implement proper access control mechanisms to validate and sanitize user inputs.
  • Regularly update and maintain your ColdFusion installations to mitigate potential vulnerabilities.
  • Monitor and audit access logs to detect any unauthorized access attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.