Hey I know this has been discussed to death but I ...
# adobe
m
Hey I know this has been discussed to death but I got an official request to find something from Adobe that says they are working on a log4j solution for the 1.x version that still remains. I haven't found anything that says this will be addressed in Update 14. Is there such a thing that is from Adobe that says they are working on it? I was asked to provide this for a report. Does anyone have anything or has there been such a release?
s
@Mark Takata (Adobe) can hopefully provide an update. The only official responses I can find talk only about the 2.x vulnerability and fixes (and claim 1.x is "not affected" but, as we now know, it has vulnerabilities of its own that do need to be addressed).
m
Thanks Sean. I'm trying to provide them with an official update as this will be documented in a report.
b
@malllory.woods Both @Mark Takata (Adobe) and @priyank_adobe have said as much here in Slack, but I'm not aware of any official Adobe doc which promises when the fix will release.
m
Agreed. I think we are on the right track from what I have gotten in email. Thanks
p
Hi Everyone, please try this.
Please try this. 1. Replace all 2.17.1 jars in cfusion\lib directory after update 13. Follow the article https://helpx.adobe.com/coldfusion/kb/log4j-2-17-0-vulnerability-coldfusion.html 2. Remove log4j 1.2.15 jar and log4j-to-slf4j-2.17.1.jar from in <cf_root>\lib directory 3. Add log4j-1.2-api-2.17.1.jar in cfusion\lib folder. 4. Add the jvm argument “_-Dlog4j1.compatibility=true_” 5. Restart CF.
👍 2
These instructions for CF2018, I will confirm and share the instruction for CF2021.
m
@priyank_adobe, While I have you hear, will a complete back up of the cfusion directory be the safest way to try this in case it fails and CF won't start?
b
Nice, is this documented somewhere publicly as a workaround? If not, you should post it in the Adobe CF forum.
p
@malllory.woods Sure, always take backup before you replace or delete anything from CF directory.
✔️ 1
@bdw429s It is not yet documented as we are working on update release soon. Will check if this can be posted in Helpx or in Forums.
👍 2
m
Thank you Priyank for this. I know you and the team have been working hard getting the official stuff together, appreciate you stepping in here! ❤️
1
m
I appreciate the update