richard.herbert
11/08/2022, 3:57 PMzackster
11/08/2022, 4:00 PMbdw429s
11/08/2022, 4:00 PMbdw429s
11/08/2022, 4:00 PMcarehart
11/08/2022, 4:01 PMbdw429s
11/08/2022, 4:01 PMbdw429s
11/08/2022, 4:02 PMrichard.herbert
11/08/2022, 4:02 PMcarehart
11/08/2022, 4:02 PMbdw429s
11/08/2022, 4:03 PMcommons-text-1.10.0.jar
carehart
11/08/2022, 4:03 PMbdw429s
11/08/2022, 4:03 PMBundle-SymbolicName: org.apache.commons.commons-text
bdw429s
11/08/2022, 4:04 PMcarehart
11/08/2022, 4:06 PMbdw429s
11/08/2022, 4:06 PMrichard.herbert
11/08/2022, 4:14 PMrichard.herbert
11/08/2022, 4:22 PMIf you need an “official” answer, e-mail PSIRT@adobe.comHummm, I got fobbed off with this /cc @Mark Takata (Adobe)
Please reach out to ColdFusion support team on this topic (support@coldfusionsupport.zendesk.com) as they are in direct touch with ColdFusion engineering team.
carehart
11/08/2022, 4:26 PMScott Bennett
11/08/2022, 4:28 PMcarehart
11/08/2022, 4:28 PMzackster
11/08/2022, 4:31 PMzackster
11/08/2022, 4:32 PMScott Bennett
11/08/2022, 4:33 PMScott Bennett
11/08/2022, 4:33 PMScott Bennett
11/08/2022, 4:35 PMScott Bennett
11/08/2022, 4:36 PMzackster
11/08/2022, 4:37 PMScott Bennett
11/08/2022, 4:40 PMrichard.herbert
11/08/2022, 4:41 PMApache commons-text jar is not used in CF2021 and CF2018. Hence, we are not impacted by this vulnerability.
If you are using this third-party jar, then it is recommended to upgrade to Apache Commons Text 1.10.0.
Scott Bennett
11/08/2022, 4:43 PMScott Bennett
11/08/2022, 4:46 PMScott Bennett
11/08/2022, 4:47 PMMark Takata (Adobe)
11/08/2022, 4:47 PMMark Takata (Adobe)
11/08/2022, 4:47 PMzackster
11/08/2022, 4:48 PMMark Takata (Adobe)
11/08/2022, 4:50 PMzackster
11/08/2022, 4:50 PMrichard.herbert
11/08/2022, 4:52 PMzackster
11/08/2022, 4:57 PMrichard.herbert
11/08/2022, 4:59 PMzackster
11/08/2022, 5:00 PMrichard.herbert
11/08/2022, 5:02 PMScott Bennett
11/08/2022, 5:02 PMScott Bennett
11/08/2022, 5:03 PMzackster
11/08/2022, 5:04 PMMark Takata (Adobe)
11/08/2022, 5:04 PMzackster
11/08/2022, 5:04 PMrichard.herbert
11/08/2022, 5:05 PMzackster
11/08/2022, 5:05 PMrichard.herbert
11/08/2022, 5:06 PMzackster
11/08/2022, 5:08 PMScott Bennett
11/08/2022, 5:11 PMMark Takata (Adobe)
11/08/2022, 5:41 PMbdw429s
11/08/2022, 5:42 PMScott Bennett
11/08/2022, 5:46 PMScott Bennett
11/08/2022, 5:47 PMzackster
11/08/2022, 6:20 PMrichard.herbert
11/08/2022, 6:52 PMIt seemed like a great idea at the timeI think I still have that t-shirt 🤔
Scott Bennett
11/08/2022, 7:18 PMrichard.herbert
11/08/2022, 7:19 PMMark Takata (Adobe)
11/08/2022, 7:30 PMScott Bennett
11/08/2022, 7:31 PMScott Bennett
11/08/2022, 7:32 PMScott Bennett
11/08/2022, 7:33 PMScott Bennett
11/08/2022, 7:35 PMScott Bennett
11/08/2022, 7:45 PMScott Bennett
11/08/2022, 7:46 PMScott Bennett
11/08/2022, 7:47 PMMark Takata (Adobe)
11/08/2022, 8:11 PMMark Takata (Adobe)
11/08/2022, 8:13 PMMark Takata (Adobe)
11/08/2022, 8:13 PMScott Bennett
11/08/2022, 8:14 PMMark Takata (Adobe)
11/08/2022, 8:19 PMseancorfield
<cfexecute> or <cfabort> -- there is no <cftry>
, ...