{"id":"CVE-2023-38205","details":"Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.","modified":"2026-03-14T12:08:15.336388Z","published":"2023-09-14T08:15:07.767Z","references":[{"type":"ADVISORY","url":"https://helpx.adobe.com/security/products/coldfusion/apsb23-47.html"},{"type":"ADVISORY","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-38205"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-38205.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"2018-NA"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update1"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update10"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update11"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update12"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update13"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update14"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update15"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update16"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update18"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update2"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update3"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update4"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update5"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update6"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update7"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update8"}]},{"events":[{"introduced":"0"},{"last_affected":"2018-update9"}]},{"events":[{"introduced":"0"},{"last_affected":"2021-NA"}]},{"events":[{"introduced":"0"},{"last_affected":"2021-update1"}]},{"events":[{"introduced":"0"},{"last_affected":"2021-update2"}]},{"events":[{"introduced":"0"},{"last_affected":"2021-update3"}]},{"events":[{"introduced":"0"},{"last_affected":"2021-update4"}]},{"events":[{"introduced":"0"},{"last_affected":"2021-update5"}]},{"events":[{"introduced":"0"},{"last_affected":"2021-update6"}]},{"events":[{"introduced":"0"},{"last_affected":"2021-update7"}]},{"events":[{"introduced":"0"},{"last_affected":"2021-update8"}]},{"events":[{"introduced":"0"},{"last_affected":"2023-NA"}]},{"events":[{"introduced":"0"},{"last_affected":"2023-update1"}]},{"events":[{"introduced":"0"},{"last_affected":"2023-update2"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}