http://coldfusion.com logo
Docs
Join the conversationJoin Slack
Channels
adobe
advent-of-code
auwcl
aws
books
bot-dev
box-products
cfeclipse
cfkrauts
cflint
cfml-beginners
cfml-general
cfml-tuning
cfsummit2022
cfwheels
ci
community_courses
css
devops-general
docker
docker-commandbox
documentation
events
friday-puzzle
fusion-reactor
fw1
ide
java-and-jvm
javascript
jobs
jobs-non-us
linen-dev
lucee
masacms
meta
migrations
mura
music
nosql
object-oriented
orm
perf-monitor
prog-general
slack-help
sql
taffy
testing
version-control
vuejs
water-cooler
Powered by Linen
adobe
  • j

    jc

    03/08/2023, 5:15 PM
    I am currently working with scheduled task event handlers and I was wondering if there was any documentation in regards to the
    fireInstanceID
    returned in the handler functions ( I could not find any ). At the moment I am using
    bigint
    to store it as
    int
    was too small, but I wanted to confirm this was safe to continue to use as I am using the event handler to keep a log of task execution, completions and errors if any.
  • t

    Tim

    03/09/2023, 3:56 PM
    (i was wrong, the time was "not quite yet")
    m
    2 replies · 2 participants
  • m

    Mark Takata (Adobe)

    03/09/2023, 4:59 PM
    The time is here, the time is now! CANCEL ALL YOUR WEEKEND PLANS! 😄 We are pleased to announce the opening of the CF Fortuna Open #Beta, now available on the Adobe Prerelease site! Features available in this release include: * GraphQL Client (native GQL support for consuming GraphQL endpoints) * Google Cloud Platform (FireStore) * Google Cloud Platform (GCPStorage) * Google Cloud Platform (PubSub) * Central Configuration Service * HTML to PDF engine upgrade * PMT Integrations for GCP (Firestore, Pub/Sub, Storage monitoring) * JSON Web Tokens * SSO CF Administrator (LDAP/SAML support) If you are interested in taking part, please sign up for free here to download installers & documentation for Windows, Linux and Mac platforms (as well as Docker!) https://www.adobeprerelease.com/beta/48C2D737-9CB4-445E-E39C-90CB6381919A Docker files available from Docker Hub and AWS ECR. DockerHub image: adobecoldfusion/fortuna:latest AWS ECR: public.ecr.aws/adobe/fortuna:latest FOR BUGS & ISSUES, PLEASE USE THE OFFICIAL PRERELEASE FORUMS (Engineers & support staff are assigned to watch the forums, which are now separated into all of the new features, including documentation for that feature.)
    👍 6
    s
    s
    +3
    29 replies · 6 participants
  • j

    jakobward

    03/11/2023, 12:08 AM
    I just ran the CF2021 installer again on my LINUX system to change the user. Websockets did not kick back on so I uninstalled the package and attempted to reinstall. Now I am getting an encryption error: “An error has occurred while installing the package websocket. Exception : An error occurred while trying to encrypt or decrypt your input string: Given final block not properly padded. Such issues can arise if a bad key is used during decryption.” Anyone?
    m
    5 replies · 2 participants
  • m

    Mark Berning

    03/13/2023, 1:51 PM
    It looks like cffiddle.org is down
    {
      "status": 500,
      "error": "None",
      "message": "I/O error on POST request for \"<http://cf2021.cffiddle.org:8500/cffiddle/c85fa036-5a93-423a-b748-4f0852e91d64/b0faac60-e774-4e5c-aff0-ce794e966d29/tmp_9c697291-50c9-4fad-b3ff-8dc1e0db29b8.cfm?__fiddlecall=true&__sandbox=c85fa036-5a93-423a-b748-4f0852e91d64&__appid=b0faac60-e774-4e5c-aff0-ce794e966d29>\": Connect to <http://cf2021.cffiddle.org:8500|cf2021.cffiddle.org:8500> [<http://cf2021.cffiddle.org/10.0.0.4|cf2021.cffiddle.org/10.0.0.4>] failed: Connection refused (Connection refused); nested exception is org.apache.http.conn.HttpHostConnectException: Connect to <http://cf2021.cffiddle.org:8500|cf2021.cffiddle.org:8500> [<http://cf2021.cffiddle.org/10.0.0.4|cf2021.cffiddle.org/10.0.0.4>] failed: Connection refused (Connection refused)",
      "timeStamp": 1678715421916,
      "path": null
    }
    s
    r
    +1
    5 replies · 4 participants
  • m

    Mark Takata (Adobe)

    03/14/2023, 3:47 PM
    ANNOUNCEMENT: CF2021 & CF2018 Security Updates https://community.adobe.com/t5/coldfusion-discussions/released-coldfusion-2021-and-2018-march-2023-security-updates/td-p/13649873
    a
    g
    +3
    12 replies · 6 participants
  • s

    seancorfield

    03/15/2023, 5:21 AM
    Did we ever get a better way to create Java objects than
    createObject()
    ? I think Lucee has a more integrated syntax but I can't remember whether the tickets requesting better syntax in ACF ever happened?
    b
    m
    5 replies · 3 participants
  • s

    salted

    03/15/2023, 9:51 AM
    @carehart can you ping this channel when you post the update to your comment on the adobe post RE the latest exploit?
  • s

    salted

    03/15/2023, 10:03 AM
    Also in the latest bulletin it says you’ve added jvm flags wrt to the exploit but not a) whether we should use them or just apply the update and b) what the correct setting is.
    In this release, we’ve addressed some security vulnerabilities and added the following jvm flags to that effect.
    -Dcoldfusion.cfclient.enable=true/false
    -Dcoldfusion.cfclient.allowNonCfc=true/false
    m
    s
    4 replies · 3 participants
  • s

    salted

    03/15/2023, 10:03 AM
    so cool that you added them but are they required for mitigation and if so is it true or false they should be set to?
  • s

    salted

    03/15/2023, 10:04 AM
    (@saghosh)
  • s

    salted

    03/15/2023, 10:05 AM
    Also the UK version of the update page doesn’t have update 16 listed
  • s

    saghosh

    03/15/2023, 10:12 AM
    @salted The other EN pages are getting localized as I write. Usually takes 24-48 hrs. Meanwhile, you can refer the EN page for a while.
  • s

    saghosh

    03/15/2023, 10:13 AM
    Can you pls send me the url @salted I'll get it checked?
  • s

    salted

    03/15/2023, 10:14 AM
    https://helpx.adobe.com/uk/coldfusion/kb/coldfusion-2018-updates.html
  • r

    rstewart

    03/17/2023, 12:46 PM
    I’m giving @carehart a quick shout-out for his most recent blog post about the most recent ColdFusion updates and the additional information about what that update addresses and steps needing to be taken. Thank you, Charlie. https://www.carehart.org/blog/2023/3/17/coldfusion_march_2023_emergency_update
    ⭐ 11
    🤘 1
    👍 2
    🙌🏻 1
    a
    b
    +3
    17 replies · 6 participants
  • l

    Leon Miller-Out

    03/17/2023, 3:14 PM
    Has anyone else had trouble with the GUI updater (in CFIDE) failing to apply updates?
    j
    h
    +1
    8 replies · 4 participants
  • l

    Leon Miller-Out

    03/17/2023, 3:44 PM
    The Manual Install instructions are atrociously bad. All I had to do was to download the hotfix jar and run it as root. I don’t know what all of that other stuff about unzipping and “the repository” and editing XML files was about.
    👍 1
    j
    m
    4 replies · 3 participants
  • j

    Jim Priest

    03/17/2023, 5:59 PM
    Adobe's response to this latest patch seems a bit 'muted'. It reads very much like every other recent CF update. Yet reading Charlie's post (thanks Charlie!!) it seems like a very serious situation.
    💯 2
    👍 2
    ❤️ 1
    p
    r
    +1
    3 replies · 4 participants
  • e

    emmet

    03/17/2023, 10:42 PM
    Cockroaches and CF11 will be all thats left of humanity one day. Thanks for keeping it alive @carehart!
    🎯 1
    c
    1 reply · 2 participants
  • m

    mike42780

    03/20/2023, 2:48 AM
    After updating Coldfusion 2021 to update 6, I'm greeted by "The administrator module is not installed." It recommends to use cfpm to "install administrator". This doesn't work and just returns null twice. The website still loads luckily. Any idea what broke or how to fix it. The install log shows 1551 Successes and 0 issues. Thanks.
    s
    7 replies · 2 participants
  • s

    salted

    03/20/2023, 11:31 AM
    Just looking for a bit of clarification on generatebcrypthash and whether it tacks on a salt itself or I should do so before hashing?
  • s

    salted

    03/20/2023, 11:31 AM
    can’t seem to find info one way or another
  • m

    Michael Miller

    03/20/2023, 2:39 PM
    After installing update 16 on ACF 2018 this weekend, we are greeted with "Reason: SERVER ERROR - Error occurred while generating PDF" errors all morning. The command on this line is: cfhtmltopdf (which is the only place in our code we use this. We've always gone old school with cddocument... Has anyone else seen an error like this? I did restart the "ColdFusion2018Add-onServices" but it did not help.
    m
    m
    +1
    10 replies · 4 participants
  • s

    salted

    03/21/2023, 10:01 AM
    Just looking for a bit of clarification on generatebcrypthash and whether it tacks on a salt itself or I should do so before hashing?
    Anyone Adobe seen this and have an answer or a pointer to docs for me?
    a
    6 replies · 2 participants
  • c

    Chris Tierney

    03/21/2023, 5:01 PM
    After installing ACF 2018 u16 w/ JVM 11.0.18 last night, our app has blown up. It appears the arrow operators/Lambdas have been regressed. This has been reproduced locally. "varB" is a query results with four columns.
    local.varA = local.get_varB.reduce( (val, row) => {
        val.append(row);
        return val;
    }, [] );
    returns ...$func_CF_ANONYMOUSCLOSURE_413 in the try/catch cause message. by switching the arrow operator to a function, the code starts working. The "regressed" code fix below works:
    local.varA = local.get_varB.reduce( function(val, row) {
        val.append(row);
        return val;
    }, [] );
    I am planning on reporting this to Adobe (@sandip_halder) but wanted to see if anyone had any input on this or have hear the same?
    2 replies · 1 participant
  • a

    aliaspooryorik

    03/21/2023, 5:03 PM
    I think you've posted the same code twice? I see no arrow function @Chris Tierney
  • c

    Chris Tierney

    03/21/2023, 5:11 PM
    Thanks... I'm looking.
    a
    2 replies · 2 participants
  • b

    bdw429s

    03/21/2023, 7:41 PM
    @Mark Takata (Adobe) I'm looking through the SQS docs today and wondering if Adobe built any event gateway integrations with this as it would be a perfect fit to be able to use the
    sendGatewayMessage()
    BIF and register a gateway listener to respond to incoming messages with SQS as the backend. It would especially solve the issue of creating a listener, which ATM would require you to build your own CFThread plumbing with long polling enabled for a queue, but all of this could be abstracted perfectly into an event gateways listener that simply response to new messages like the existing ActiveMQ one does.
    m
    1 reply · 2 participants
  • r

    rstewart

    03/21/2023, 8:03 PM
    @sandip_halder @Mark Takata (Adobe) Our cybersecurity scanning team is pitching a fit about the old version of Apache Log4j currently still included in ColdFusion 2018. Specifically, they are complaining about the version 1.2.15 present within
    cfusion/lib/cf-logging.jar
    . Thoughts on how best to respond?
    s
    a
    +1
    12 replies · 4 participants
Powered by Linen
Title
r

rstewart

03/21/2023, 8:03 PM
@sandip_halder @Mark Takata (Adobe) Our cybersecurity scanning team is pitching a fit about the old version of Apache Log4j currently still included in ColdFusion 2018. Specifically, they are complaining about the version 1.2.15 present within
cfusion/lib/cf-logging.jar
. Thoughts on how best to respond?
s

sandip_halder

03/21/2023, 8:29 PM
@rstewart Ron, the version might be 1.2.15 but we have mitigated the risks associated with that file. So, even though the file version is same, but, it is not vulnerable anymore
👎 1
r

rstewart

03/21/2023, 8:34 PM
@sandip_halder OK if I DM you RE this?
a

Adam Cameron

03/21/2023, 9:29 PM
So let me get this straight. This isn't some wayward Log4J.jar sitting around in some add-on package CF uses (and perhaps not even the logging features thereof), this is in cf-logging.jar - CF's own logger, written specifically for the product - and you still have a jar file in there that's gonna set off everyone's security scanners regarding the most well known exploit in the last n years? And Adobe's position is "its fine. Trust us".
This is even better than Lucee's "ah we use such an old version of Log4J you needn't worry about that. [beat] Shit what do you mean the older versions have different vulnerabilities in them!??"
#notActuallyBetter
j

jclausen

03/21/2023, 10:35 PM
I have submitted 4-5 bug reports on the exact same scan issues. I scanned 2023 last week and it still has Log4J1
a

Adam Cameron

03/21/2023, 10:36 PM
@Mark Takata (Adobe) come on man. What's going on here?
j

jclausen

03/21/2023, 10:36 PM
I posted my findings from the latest scans of the beta here: https://forums.adobeprerelease.com/fortunabeta/discussion/24/security-scan-results/p1?new=1
a

Adam Cameron

03/21/2023, 10:36 PM
(I had just assumed the CF2018 / CF2021 were gonna turn out to be hasty patch jobs with the proper fix in CF2023. But... no... 😞
Oh yeah, I remember seeing it now
aaaaand... the std level of engagement from the Adobe CF Team I see.
j

jclausen

03/21/2023, 10:37 PM
Not specifics, but the count is still staggering - over 190 CVE’s or GHSA’s ranked “Critical” or “High” packaged in.
View count: 2