Copy link to clipboard
Copied
Does Adobe intend to ever update the main installer for Adobe ColdFusion 2021?
Reasoning: The installer as it is includes a log4j vulnerability that some network scanners are detecting. In my environment, the network scanner detected the log4j vulnerability that was present prior to being able to install Update 4 and performing cleanup on the hf-updates directory.
Will the installer be updated? Is there a way for an administrator to be able to streamline the update into the initial installation?
Copy link to clipboard
Copied
Yes, a new installer is occasionally created. The last was in sep '21, which built in update 2 and Java 11.0.11. There was not a new one incorporating updates 3 or 4.
And no, there's no way to get the uodates added other than running the update (whether from the cf admin or via the command line, as discussed in the update technotes).
Fwiw, the Adobe CF docker images DO come pre-configured with each latest update. Somehow, creating installers is seen by the team as too complicated, perhaps due to the multiple os's (whereas there's only a single docker image, which is Linux only).