{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2024-20767",
  "revision": 1,
  "title": "Adobe ColdFusion — access control gap reaches restricted files",
  "summary": "ColdFusion 2023.6, 2021.12 and earlier do not enforce access control properly, so an attacker who can reach the administration panel reads and changes files that should be out of reach.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 7.4,
    "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
    "version": "3.1"
  },
  "epss": 0.98514,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "high",
    "kev_added": "2024-12-16",
    "prerequisites": "Network access to the ColdFusion administration panel."
  },
  "remediation": {
    "patch_available": true
  },
  "mitre_attack": [
    "T1190"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Apply Adobe bulletin APSB24-14 now and take the administration panel off the internet; exploitation probability is near certain.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2024-20767",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2024-20767",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2024-20767",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20767",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://helpx.adobe.com/security/products/coldfusion/apsb24-14.html"
    },
    {
      "type": "writeup",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-20767"
    }
  ],
  "published_at": "2024-03-18T12:15:06.870Z",
  "issued_at": "2026-09-24T12:03:01.274Z",
  "tags": [
    "adobe",
    "coldfusion",
    "access-control",
    "kev"
  ]
}
