Are there Log4j vulnerabilities in ColdFusion2021, Update 18?
Hi, all.
I recently asked about Log4j vulnerabilities in CF2023, and learned that there are not any known at this time. Now, I need to ask whether CF2021, Update 18 has any Log4j vulnerabilities.
The main reason I ask is because I have CF2021 Update 13 installed locally, and when I match the files that @Charlie Arehart mentioned in one of his linked articles, I find that of the files he indicates should exist in (CF_Home)/lib folder prior to file replacement with 2.17.1 versions:
- log4j-core-2.16.0.jar
- log4j-api-2.16.0.jar
- log4j-to-slf4j-2.16.0.jar
My directory has only these unversioned files (with no corresponding file for log4j-to-slf4j)
- log4j-core.jar
- log4j-api.jar
Possibly the files I have are version 2.16.0, although not named as such? I'm not sure how to check the versions programmatically, and I don't see that the installed Log4j versions are listed anywhere in the CF Admin.
In a nutshell, will updating to CF2021 Update 18 remove all known Log4j vulnerabilities, or would further fixes still be necessary?
Thank you!
