• Global community
    • Language:
      • Deutsch
      • English
      • Español
      • Français
      • Português
  • 日本語コミュニティ
    Dedicated community for Japanese speakers
  • 한국 커뮤니티
    Dedicated community for Korean speakers
Exit
2

NOW LIVE! Adobe ColdFusion 2023 and 2021 November security updates

Adobe Employee ,
Nov 14, 2023 Nov 14, 2023

Copy link to clipboard

Copied

We are pleased to announce that we have released security updates to ColdFusion (2023 release) Update 6 and ColdFusion (2021 release) Update 12.

 

These updates resolve critical vulnerabilities that could lead to the deserialization of untrusted data, improper access control, and others. For more information, view the security bulletin,  APSB23-52.

 

Where do I download the updates from

Download the updates from the following locations:

 

What do the updates contain

For more information, view the following tech notes:

 

Are the Docker images available

The images are available on the Docker hub and ECR.

 

Please update your ColdFusion versions and provide us with your valuable feedback.

Views

1.5K

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Explorer ,
Nov 14, 2023 Nov 14, 2023

Copy link to clipboard

Copied

CF2023 Update 6 is not listed in CF Admin when installed with the refreshed ColdFusion 2023 installer.

Please update the updates.xml:

https://cfdownload.adobe.com/pub/adobe/coldfusion/xml/updates.xml
need to add an entry for <cfhf_server version="2023,0,05">. Currently there is only 2023,0,0.

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Expert ,
Nov 14, 2023 Nov 14, 2023

Copy link to clipboard

Copied

I have not found that to be true. Instead, what I find can happen (with about every update) is that something between your cf server and the Adobe server that serves that xml. You may want to try to visit it on a browser on your server. I'm not saying it WILL help, but it could. Otherwise in time you will find the update appears. You could also download it manually, as discussed and offered in the update technote. 


/Charlie (troubleshooter, carehart.org)

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Explorer ,
Nov 15, 2023 Nov 15, 2023

Copy link to clipboard

Copied

updates.xml has been changed and this issue is resolved. Thank you adobe.

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Expert ,
Nov 15, 2023 Nov 15, 2023

Copy link to clipboard

Copied

There was nothing for Adobe to do. Did you read my previous reply? You simply benefited from the expiring of whatever cache held up you seeing the updated xml. Again, I got it yesterday, the day it went live. 


/Charlie (troubleshooter, carehart.org)

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Explorer ,
Nov 15, 2023 Nov 15, 2023

Copy link to clipboard

Copied

I have found a post on CFML Slack that there have been some changes made and I confirmed the updates.xml has been changed.

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Explorer ,
Nov 16, 2023 Nov 16, 2023

Copy link to clipboard

Copied

You may want to post these to the main update pages for CF 2021 (https://helpx.adobe.com/ca/coldfusion/kb/coldfusion-2021-updates.html) and CF 2023 (https://helpx.adobe.com/ca/coldfusion/kb/coldfusion-2023-updates.html), the are still showing the updates from October and not the most recent ones from November 14th.

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Adobe Employee ,
Nov 16, 2023 Nov 16, 2023

Copy link to clipboard

Copied

Thanks @neochad Let me check with my localization team.

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Adobe Employee ,
Nov 17, 2023 Nov 17, 2023

Copy link to clipboard

Copied

Hi @neochad 

Please check the pages. They're updated now.

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Explorer ,
Nov 23, 2023 Nov 23, 2023

Copy link to clipboard

Copied

Apologies for the late reply, that page is showing properly now. Though I also noticed that the coldfusion downloads page also shows the same issue. https://helpx.adobe.com/ca/coldfusion/kb/coldfusion-downloads.html#downloads3 and https://helpx.adobe.com/coldfusion/kb/coldfusion-downloads.html#downloads3 will show different JDK downloads as well.

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Adobe Employee ,
Nov 23, 2023 Nov 23, 2023

Copy link to clipboard

Copied

LATEST

Thanks @neochad let me check. could be the same issue.

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Resources
Documentation