Coldfusion Vulnerability Message
Hi there,
We have Coldfusion 2021 and are on update 18. However we have some security software reporting a vulnerability and it turns out the file bundlesdependency.json under the folder C:\ColdFusion2021\bundles has references to version 2021.0.0.323925. I can see jar files in that folder for each of the bundles it is referencing. Do I simply update the version in the bundlesdependency.json file to be the latest version number for that file? For for example awslambda has these files in that folder:
awslambda-2021.0.0.323925.jar
awslambda-2021.0.02.328618.jar
awslambda-2021.0.05.330109.jar
awslambda-2021.0.11.330247.jar
awslambda-2021.0.17.330334.jar
Do I simply update the value from 2021.0.0.323925 to 2021.0.17.330334 as below?
"bundle" : "awslambda",
"version" : "2021.0.17.330334", -- HERE
"description" : "The awslambda package helps you invoke AWS lambda functions"
I would take a copy of the bundlesdependency.json file before obviously in case I needed to roll back. Why did this file not get updated when I update Coldfusion? Sorry I am a newbie so this might be a simple question 🙂
