ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier...
Low severity
Unreviewed
Published
Aug 18, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Aug 18, 2025
Published to the GitHub Advisory Database
Aug 18, 2025
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to limited file system read. A high-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction.
References