Adobe Product Line Security Update Advisory

Overview

 

Adobe(https://adobe.com) has released a security update that addresses a vulnerability in its supplied products. Users of affected systems are advised to update to the latest version.

 

Affected Products

 

ColdFusion 2023 update 11 or below versions

ColdFusion 2021 update 17 or below versions

 

Resolved Vulnerabilities

 

Arbitrary file read vulnerability due to lack of pathname restrictions in ColdFusion (CVE-2024-53961)

 

Vulnerability Patches

 

The following product-specific vulnerability patches were made available in the December 23, 2024 update.

ColdFusion 2023 Update 12

ColdFusion 2021 Update 18

 

Referenced Sites

 

Security Bulletins and Advisories

https://helpx.adobe.com/security.html/security/security-bulletin.ug.html

APSB24-107 : Security update available for Adobe ColdFusion

https://helpx.adobe.com/security/products/coldfusion/apsb24-107.html

APSB24-107 : Security update available for Adobe ColdFusion

https://helpx.adobe.com/security/products/coldfusion/apsb24-107.html