ColdFusion 2025.9, 2023.20 및 이전 버전은 제한된 디렉터리에 대한 경로명 제한이 부적절한 Path Traversal 취약점의 영향을 받습니다. 이 취약점은 현재 사용자 권한으로 임의 코드 실행으로 이어질 수 있습니다. 악용에 사용자 상호작용은 필요하지 않으며 Scope는 changed입니다.
ColdFusion 2025.9, 2023.20 및 이전 버전은 제한된 디렉터리에 대한 경로명 제한이 부적절한 Path Traversal 취약점의 영향을 받습니다. 이 취약점은 현재 사용자 권한으로 임의 코드 실행으로 이어질 수 있습니다. 악용에 사용자 상호작용은 필요하지 않으며 Scope는 changed입니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
영향 제품·버전
제품 Adobe ColdFusion 2025, ColdFusion 2023, coldfusion
영향 버전 Adobe ColdFusion 2025, ColdFusion 2023, coldfusion <= 9, <= 20, 2023, 2025
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
조치 기한: 2026.07.10
해당사항 확인방법
Adobe ColdFusion 2025, ColdFusion 2023, coldfusion의 현재 전체 버전이 공식 영향 범위(Adobe ColdFusion 2025, ColdFusion 2023, coldfusion <= 9, <= 20, 2023, 2025)에 포함되는지 확인합니다. OS를 선택하면 해당 OS의 제품·패키지·KB·APAR 확인 명령만 표시됩니다.
조치방안
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
조치 후 확인사항
패치 후 같은 명령으로 전체 버전을 다시 확인해 수정 버전은 공급사 공식자료 확인 필요 기준을 충족하는지 확인합니다. 이어서 경로 조작·임의 파일 접근 관련 오류·공격 흔적이 새로 발생하지 않는지 확인합니다.