Announcing CF update released Jul 14 2023: a second priority 1 security update in one week
For more on the update, and some additional thoughts, read on.
For more on the update, and some additional thoughts, read on.
A table of Java versions supported by given ColdFusion versions
ColdFusion 2025 released, Feb 25 2025: resources and my initial thoughts
Announcing Java updates of Jan 21, 2025 for 8, 11, 17, 21, and 23: thoughts and resources
Last chance to save 25% off CF2023, for those on CF2018 and earlier
Beware that ColdFusion 2021 end-of-life (and end of updates) is coming Nov 2025, and your options
ColdFusion 2025 released, Feb 25 2025: resources and my initial thoughts
Charlie Arehart said:
Uday, I assume you're speaking in your role as a member of the cf team. Thanks.
But can you clarify
...
[more]
ColdFusion 2025 released, Feb 25 2025: resources and my initial thoughts
Uday Ogra said:
Christopher, that periodic check in call will be made by running CF server
ColdFusion 2025 released, Feb 25 2025: resources and my initial thoughts
Charlie Arehart said:
Christopher, I don't work for Adobe so can't answer that last question. :-) I'm just a messenger, po
...
[more]
ColdFusion 2025 released, Feb 25 2025: resources and my initial thoughts
Christopher said:
So if I'm understanding the new licensing correctly for those of us who previously would purchase a
...
[more]
Easily finding cached/old versions of a site/page when it's down or gone
Charlie Arehart said:
I'm sorry to hear of your plight. What you ask is well beyond the scope of this post, but I realize
...
[more]
I will note that while that post indicates that "There is currently no mitigation", that may not be the final/complete answer. Note how it refers to the _cfclient querystring, and notice that in my first post last week (on the Jul 11 CF update), I did point out how my March blog post on the previous CF update discussed ways to BLOCK ALL REQUESTS using that _cfclient querystring. I also elaborate there on what it's about, how one can determine if they may have any legit use of it (most do not), and much more. See https://www.carehart...
As I've said elsewhere, it's just not clear how many of the recently closed vulns DO work based on the _cfclient querystring. That post is about all we have to go on, as I've not seen any others. While those on cf2018 and above can apply these fixes to address what Adobe has found, it's just not clear (for now) what those on cf2016 can or should do, other than block requests with that querystring.