CFzip on ColdFusion (2021 Release) Enterprise

New Here ,
Feb 08, 2021 Feb 08, 2021

Copy link to clipboard

Copied

After the upgrade to CF 2021 Enterprise, when we attempt to unzip a file we are getting a new error message I have not seen before:

 

"Exception while extracting 69_campaign.zip: Uncompressed contents cross maximum permissible size of 405.52734375 KB"

 

The file is only 41526Kb in size (small) and the import routine worked perfectly BEFORE the upgrade. I can find no info on this error anywhere - help?

Views

98

Likes

Translate

Translate

Report

Report
Community Guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines

correct answers 1 Correct Answer

New Here , Feb 09, 2021 Feb 09, 2021
FIXED - for anyone else experiencing this issue, this below from Adobe Support: With the 2021 release a new setting has been added: “maxUnzipRatio” to prevent ZIP bomb attack. The UI for this will come in the next update. For time being, you can use the below java argument and allow unzip operation. Take a back up of jvm.config file at C:\ColdFusion2021\cfusion\bin, add the below argument and restart the ColdFusion service. -Dcoldfusion.zip.maxunzipratio=1024 For example: java.args=-Xdebug -...

Likes

Translate

Translate
New Here ,
Feb 09, 2021 Feb 09, 2021

Copy link to clipboard

Copied

LATEST

FIXED - for anyone else experiencing this issue, this below from Adobe Support:

 

With the 2021 release a new setting has been added: “maxUnzipRatio” to prevent ZIP bomb attack. The UI for this will come in the next update. For time being, you can use the below java argument and allow unzip operation.

Take a back up of jvm.config file at C:\ColdFusion2021\cfusion\bin, add the below argument and restart the ColdFusion service.

-Dcoldfusion.zip.maxunzipratio=1024

For example:

java.args=-Xdebug -Xrunjdwp:transport=dt_socket,server=y,suspend=n,address=5021 -server --add-opens=java.rmi/sun.rmi.transport=ALL-UNNAMED -Dcoldfusion.zip.maxunzipratio=1024 --add-opens=java.base/java.nio=ALL-UNNAMED --add-opens=java.base/java.lang=ALL-UNNAMED 

 

For the record, paid support escalated this issue within an hour and the fix was delivered within 24 hours - THANK YOU!

 

Carmen

Likes

Translate

Translate

Report

Report
Community Guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines