CVE Vulnerabilities

CVE-2025-30287

Improper Authentication

Published: Apr 08, 2025 | Modified: Apr 18, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of the current user. A low privileged attacker with local access could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction in that a victim must be coerced into performing actions within the application and scope is changed.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Coldfusion Adobe 2021 (including) 2021 (including)
Coldfusion Adobe 2021-update1 (including) 2021-update1 (including)
Coldfusion Adobe 2021-update10 (including) 2021-update10 (including)
Coldfusion Adobe 2021-update11 (including) 2021-update11 (including)
Coldfusion Adobe 2021-update12 (including) 2021-update12 (including)
Coldfusion Adobe 2021-update13 (including) 2021-update13 (including)
Coldfusion Adobe 2021-update14 (including) 2021-update14 (including)
Coldfusion Adobe 2021-update15 (including) 2021-update15 (including)
Coldfusion Adobe 2021-update16 (including) 2021-update16 (including)
Coldfusion Adobe 2021-update17 (including) 2021-update17 (including)
Coldfusion Adobe 2021-update18 (including) 2021-update18 (including)
Coldfusion Adobe 2021-update2 (including) 2021-update2 (including)
Coldfusion Adobe 2021-update3 (including) 2021-update3 (including)
Coldfusion Adobe 2021-update4 (including) 2021-update4 (including)
Coldfusion Adobe 2021-update5 (including) 2021-update5 (including)
Coldfusion Adobe 2021-update6 (including) 2021-update6 (including)
Coldfusion Adobe 2021-update7 (including) 2021-update7 (including)
Coldfusion Adobe 2021-update8 (including) 2021-update8 (including)
Coldfusion Adobe 2021-update9 (including) 2021-update9 (including)
Coldfusion Adobe 2023 (including) 2023 (including)
Coldfusion Adobe 2023-update1 (including) 2023-update1 (including)
Coldfusion Adobe 2023-update10 (including) 2023-update10 (including)
Coldfusion Adobe 2023-update11 (including) 2023-update11 (including)
Coldfusion Adobe 2023-update12 (including) 2023-update12 (including)
Coldfusion Adobe 2023-update2 (including) 2023-update2 (including)
Coldfusion Adobe 2023-update3 (including) 2023-update3 (including)
Coldfusion Adobe 2023-update4 (including) 2023-update4 (including)
Coldfusion Adobe 2023-update5 (including) 2023-update5 (including)
Coldfusion Adobe 2023-update6 (including) 2023-update6 (including)
Coldfusion Adobe 2023-update7 (including) 2023-update7 (including)
Coldfusion Adobe 2023-update8 (including) 2023-update8 (including)
Coldfusion Adobe 2023-update9 (including) 2023-update9 (including)
Coldfusion Adobe 2025 (including) 2025 (including)

Potential Mitigations

References