CVE Vulnerabilities

CVE-2020-3761

Published: Mar 25, 2020 | Modified: Jul 21, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a remote file read vulnerability. Successful exploitation could lead to arbitrary file read from the coldfusion install directory.

Affected Software

Name Vendor Start Version End Version
Coldfusion Adobe 2016 (including) 2016 (including)
Coldfusion Adobe 2016-update1 (including) 2016-update1 (including)
Coldfusion Adobe 2016-update10 (including) 2016-update10 (including)
Coldfusion Adobe 2016-update11 (including) 2016-update11 (including)
Coldfusion Adobe 2016-update12 (including) 2016-update12 (including)
Coldfusion Adobe 2016-update13 (including) 2016-update13 (including)
Coldfusion Adobe 2016-update2 (including) 2016-update2 (including)
Coldfusion Adobe 2016-update3 (including) 2016-update3 (including)
Coldfusion Adobe 2016-update4 (including) 2016-update4 (including)
Coldfusion Adobe 2016-update5 (including) 2016-update5 (including)
Coldfusion Adobe 2016-update6 (including) 2016-update6 (including)
Coldfusion Adobe 2016-update7 (including) 2016-update7 (including)
Coldfusion Adobe 2016-update8 (including) 2016-update8 (including)
Coldfusion Adobe 2016-update9 (including) 2016-update9 (including)
Coldfusion Adobe 2018 (including) 2018 (including)
Coldfusion Adobe 2018-update1 (including) 2018-update1 (including)
Coldfusion Adobe 2018-update2 (including) 2018-update2 (including)
Coldfusion Adobe 2018-update3 (including) 2018-update3 (including)
Coldfusion Adobe 2018-update4 (including) 2018-update4 (including)
Coldfusion Adobe 2018-update5 (including) 2018-update5 (including)
Coldfusion Adobe 2018-update6 (including) 2018-update6 (including)
Coldfusion Adobe 2018-update7 (including) 2018-update7 (including)

References