CVE-2024-41874
CVE-2024-41874
Título es
CVE-2024-41874
Vie, 13/09/2024 – 10:15
Tipo
CWE-502
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-41874
Descripción en
ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability by providing crafted input to the application, which when deserialized, leads to execution of malicious code. Exploitation of this issue does not require user interaction.
13/09/2024
13/09/2024
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Gravedad 3.1 (CVSS 3.1 Base Score)
9.80
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
CRITICAL
Enviar en el boletín
Off
