Heads up - technical details on CVE-2024-20767 (Co...
# adobe
b
Heads up - technical details on CVE-2024-20767 (ColdFusion Arbitrary File System Read) from APSB24-14 were disclosed a few hours ago. The good news is that exploitation will likely require direct access to the ColdFusion Tomcat server in most/many cases. I've written up some additional thoughts and compensating controls for those who can't patch right away here - https://www.hoyahaxa.com/2024/03/defending-against-cve-2024-20767.html
👀 1
👍 7
👍🏻 1