Adobe has released today an important security update for each of ColdFusion 2023 (update 4) and 2021 (update 10). (Since
CF2018 is end of life since July, there is no update for that version.) Note that
while the technotes for the updates don't mention/link to any Adobe product security bulletin (APSB), this update is indeed an update that provides important security protections, as I discuss further below.
For more resources as well as some additional thoughts on the updates (including what security matter it entails as well as some lessons learned in applying the update--especially if you may update your Java to the JVM released last month), read on.
[....Continue Reading....]
See both my section on this above and my earlier post that I point to, for more on that debate.