dswitzer
03/14/2022, 5:18 PMzackster
03/14/2022, 5:20 PMbdw429s
03/14/2022, 5:20 PMdswitzer
03/14/2022, 5:21 PMbdw429s
03/14/2022, 5:21 PMzackster
03/14/2022, 5:21 PMbdw429s
03/14/2022, 5:21 PMbdw429s
03/14/2022, 5:22 PMdswitzer
03/14/2022, 5:22 PMbdw429s
03/14/2022, 5:23 PMbdw429s
03/14/2022, 5:23 PMzackster
03/14/2022, 5:23 PMbdw429s
03/14/2022, 5:24 PMbdw429s
03/14/2022, 5:24 PMdswitzer
03/14/2022, 5:24 PMdswitzer
03/14/2022, 5:24 PMdswitzer
03/14/2022, 5:25 PMbdw429s
03/14/2022, 5:26 PMbdw429s
03/14/2022, 5:26 PMdswitzer
03/14/2022, 5:27 PMbdw429s
03/14/2022, 5:27 PMbdw429s
03/14/2022, 5:27 PMdswitzer
03/14/2022, 5:27 PMzackster
03/14/2022, 5:27 PMbdw429s
03/14/2022, 5:27 PMdswitzer
03/14/2022, 5:28 PMbdw429s
03/14/2022, 5:29 PMbdw429s
03/14/2022, 5:29 PMzackster
03/14/2022, 5:30 PMdswitzer
03/14/2022, 5:36 PMAdam Cameron
Also note, Lucee 5.3.9 will acitvley DELETE Log4j 1.x bundles.It does what?
bdw429s
03/14/2022, 6:41 PMAdam Cameron
bdw429s
03/14/2022, 6:48 PMzackster
03/14/2022, 7:06 PMzackster
03/14/2022, 7:08 PMzackster
03/14/2022, 7:09 PMbdw429s
03/14/2022, 7:09 PMCFMLEngineImpl
constructor, so it seems it would run on every server start.zackster
03/14/2022, 7:09 PMbdw429s
03/14/2022, 7:10 PMkeep the C level execs happy with their fancy infosec teamIMO, those people can and should ⢠install a fresh Lucee install ⢠manually remove these bundles as documented by Lucee if they know they're not using them
bdw429s
03/14/2022, 7:11 PMzackster
03/14/2022, 7:11 PMbdw429s
03/14/2022, 7:12 PMbdw429s
03/14/2022, 7:12 PMAdam Cameron
In order to placate one groupI also think that's a largely invented group.
bdw429s
03/14/2022, 9:33 PMbdw429s
03/14/2022, 9:34 PMbdw429s
03/14/2022, 9:35 PMAdam Cameron
zackster
03/15/2022, 12:53 PM