Adobe Product Line Security Update Advisory
Overview
Adobe(https://adobe.com) has released a security update that addresses a vulnerability in its supplied products. Users of affected systems are advised to update to the latest version.
Affected Products
ColdFusion 2023 update 11 or below versions
ColdFusion 2021 update 17 or below versions
Resolved Vulnerabilities
Arbitrary file read vulnerability due to lack of pathname restrictions in ColdFusion (CVE-2024-53961)
Vulnerability Patches
The following product-specific vulnerability patches were made available in the December 23, 2024 update.
ColdFusion 2023 Update 12
ColdFusion 2021 Update 18
Referenced Sites
Security Bulletins and Advisories
https://helpx.adobe.com/security.html/security/security-bulletin.ug.html
APSB24-107 : Security update available for Adobe ColdFusion
https://helpx.adobe.com/security/products/coldfusion/apsb24-107.html
APSB24-107 : Security update available for Adobe ColdFusion
https://helpx.adobe.com/security/products/coldfusion/apsb24-107.html