Логотип exploitDog
bind:CVE-2024-41874
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-41874

Количество 3

Количество 3

nvd логотип

CVE-2024-41874

больше 1 года назад

ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability by providing crafted input to the application, which when deserialized, leads to execution of malicious code. Exploitation of this issue does not require user interaction.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-pqq8-7w9h-7g85

больше 1 года назад

ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability by providing crafted input to the application, which when deserialized, leads to execution of malicious code. Exploitation of this issue does not require user interaction.

CVSS3: 9.8
EPSS: Средний
fstec логотип

BDU:2024-07390

больше 1 года назад

Уязвимость программной платформы ColdFusion, связанная с восстановлением в памяти недостоверных данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-41874

ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability by providing crafted input to the application, which when deserialized, leads to execution of malicious code. Exploitation of this issue does not require user interaction.

CVSS3: 9.8
24%
Средний
больше 1 года назад
github логотип
GHSA-pqq8-7w9h-7g85

ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability by providing crafted input to the application, which when deserialized, leads to execution of malicious code. Exploitation of this issue does not require user interaction.

CVSS3: 9.8
24%
Средний
больше 1 года назад
fstec логотип
BDU:2024-07390

Уязвимость программной платформы ColdFusion, связанная с восстановлением в памяти недостоверных данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
24%
Средний
больше 1 года назад

Уязвимостей на страницу