Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pf9f-7gg3-qgq3

Опубликовано: 08 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 2.4

Описание

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Access Control vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability to disrupt the availability of the application. Exploitation of this issue does not require user interaction and scope is unchanged. The vulnerable component is restricted to internal IP addresses.

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Access Control vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability to disrupt the availability of the application. Exploitation of this issue does not require user interaction and scope is unchanged. The vulnerable component is restricted to internal IP addresses.

EPSS

Процентиль: 10%
0.00035
Низкий

2.4 Low

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 2.4
nvd
7 месяцев назад

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Access Control vulnerability that could lead to a partial application denial-of-service. A high-privileged attacker could exploit this vulnerability to partially disrupt the availability of the application. Exploitation of this issue does not require user interaction and scope is unchanged. The vulnerable component is restricted to internal IP addresses.

CVSS3: 2.7
fstec
7 месяцев назад

Уязвимость программной платформы ColdFusion, связанная с недостаточной проверкой поступающих запросов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 10%
0.00035
Низкий

2.4 Low

CVSS3

Дефекты

CWE-284