Artwork

Sisällön tarjoaa Ortus Solutions. Ortus Solutions tai sen podcast-alustan kumppani lataa ja toimittaa kaiken podcast-sisällön, mukaan lukien jaksot, grafiikat ja podcast-kuvaukset. Jos uskot jonkun käyttävän tekijänoikeudella suojattua teostasi ilman lupaasi, voit seurata tässä https://fi.player.fm/legal kuvattua prosessia.
Player FM - Podcast-sovellus
Siirry offline-tilaan Player FM avulla!

Modernize or Die® - CFML News Podcast for March 14th, 2023 - Episode 188

54:13
 
Jaa
 

Manage episode 358064319 series 2508132
Sisällön tarjoaa Ortus Solutions. Ortus Solutions tai sen podcast-alustan kumppani lataa ja toimittaa kaiken podcast-sisällön, mukaan lukien jaksot, grafiikat ja podcast-kuvaukset. Jos uskot jonkun käyttävän tekijänoikeudella suojattua teostasi ilman lupaasi, voit seurata tässä https://fi.player.fm/legal kuvattua prosessia.

2023-03-14 Weekly News - Episode 188

Watch the video version on YouTube at https://youtube.com/live/v4vxEckWfYg?feature=share

Hosts:

  • Gavin Pickin - Senior Developer at Ortus Solutions
  • Daniel Garcia - Senior Developer at Ortus Solutions

Thanks to our Sponsor - Ortus Solutions
The makers of ColdBox, CommandBox, ForgeBox, TestBox and all your favorite box-es out there.
A few ways to say thanks back to Ortus Solutions:

Patreon Support ( Invigorating ) - UPDATED GOALS

We have 41 patreons:

Goal 1 - 26% - This goal would help us to fully fund the hosting of ForgeBox.io (www.forgebox.io), the ColdFusion software directory.
Goal 2 - 13% - This goal would fund the development of CommandBox CLI, so it can remain FREE and Open Source forever.
Goal 3 - 6% - This goal would help us to fully fund the Modernize or Die podcasts.

https://www.patreon.com/ortussolutions.

News and Announcements

Critical Security Update for ColdFusion APSB23-25

From Adobe

https://community.adobe.com/t5/coldfusion-discussions/released-coldfusion-2021-and-2018-march-2023-security-updates/td-p/13649873

From Foundeo

Adobe has just published a security bulletin APSB23-25, and has released security updates for ColdFusion 2018 and 2021.

We recommend installing these update as soon as possible, because one of the vulnerabilities has been actively exploited by attackers already.

https://helpx.adobe.com/security/products/coldfusion/apsb23-25.html
https://helpx.adobe.com/coldfusion/kb/coldfusion-2018-update-16.html
https://helpx.adobe.com/coldfusion/kb/coldfusion-2021-update-6.html

HackMyCF has been updated to warn you if the hotfix is missing.

It is important to note that if you are on ColdFusion 11, or 2016 that it is possible that your servers could be vulnerable to at least one of these issue as well. However, because these versions reached end of life they are no longer receiving security patches from Adobe.

One thing you can do to mitigate one of these issues is to block requests containing a variable named _cfclient. Some of the filters in FuseGuard may help prevent some attack vectors when configured to. But the best solution is to upgrade to CF2018 or 2021 and apply the patch released today.
--
Foundeo Inc.

ICYMI - Authentication Bypass Vulnerability in Mura CMS and Masa CMS (CVE-2022-47003 and CVE-2022-47002)

Mura CMS is a popular content management system written in ColdFusion/CFML. While it was originally a commercial open source product, it was re-licensed as a closed source application with the release of Mura CMS v10 in 2020. There are forked open source projects based on the last open source release of Mura CMS, including Masa CMS - which is actively maintained.

Multiple versions of Mura CMS and Masa CMS contain an authentication bypass vulnerability that can allow an unauthenticated attacker to login as any Site Member or System User.
https://hoyahaxa.blogspot.com/2023/03/authentication-bypass-mura-masa.html

ICYMI - State of the CF Union 2023 Released

Help us find out the state of the CF Union – what versions of CFML Engine do people use, what frameworks, tools etc.
https://teratech.com/state-of-the-cf-union-2023-survey

New Releases and Updates

ICYMI - CommandBox 5.8.0 Released!

We are pleased to announce the release of CommandBox 5.8.0, which comes with a handful of new features and some important library updates.

Now bundles commandbox-cfconfig, commandbox-dotenv, commandbox-update-check. Automatically installed or updated when you start CLI

Automatically sets the content type in the HTTP response for static file typesl. You can customize in server.json

Config and Module Sync - if you are authenticated to ForgeBox in the CLI, you can synchronize config settings to and from.
Web Server Case Sensitivty - forcing case sensitivity on Windows

REPL improvements

As usual, you can acquire the latest release from our download page or your favorite HomeBrew or apt/yum repo

https://www.ortussolutions.com/products/commandbox#download

https://www.ortussolutions.com/blog/commandbox-580-released

https://commandbox.ortusbooks.com/

ICYMI - First Lucee 6 Beta Released

Remember this is a BETA, so it’s not production ready, what we are looking for in this first BETA release, is for you to try and run your apps / test suites in locally and let us know how it goes for you.

https://dev.lucee.org/t/first-lucee-6-public-beta-is-available-6-0-0-346-beta/12195

Webinar / Meetups and Workshops

Ortus Event Calendar for Google

https://calendar.google.com/calendar/u/0?cid=Y181NjJhMWVmNjFjNGIxZTJlNmQ4OGVkNzg0NTcyOGQ1Njg5N2RkNGJiNjhjMTQwZjc3Mzc2ODk1MmIyOTQyMWVkQGdyb3VwLmNhbGVuZGFyLmdvb2dsZS5jb20

Ortus Webinar - March 17, 2023 - CBSecurity with Luis Majano
Friday, March 17th, at 3pm CST.
Signup Now: https://us02web.zoom.us/meeting/register/tZAsf-6hrzsuE9POBoeyMYsFPY1AN-M2x29F

Ortus Office Hours - Date TBD
Due to spring break, good friday, lots of people at Dev Nexus and CF Summit East, we might pu...

  continue reading

218 jaksoa

Artwork
iconJaa
 
Manage episode 358064319 series 2508132
Sisällön tarjoaa Ortus Solutions. Ortus Solutions tai sen podcast-alustan kumppani lataa ja toimittaa kaiken podcast-sisällön, mukaan lukien jaksot, grafiikat ja podcast-kuvaukset. Jos uskot jonkun käyttävän tekijänoikeudella suojattua teostasi ilman lupaasi, voit seurata tässä https://fi.player.fm/legal kuvattua prosessia.

2023-03-14 Weekly News - Episode 188

Watch the video version on YouTube at https://youtube.com/live/v4vxEckWfYg?feature=share

Hosts:

  • Gavin Pickin - Senior Developer at Ortus Solutions
  • Daniel Garcia - Senior Developer at Ortus Solutions

Thanks to our Sponsor - Ortus Solutions
The makers of ColdBox, CommandBox, ForgeBox, TestBox and all your favorite box-es out there.
A few ways to say thanks back to Ortus Solutions:

Patreon Support ( Invigorating ) - UPDATED GOALS

We have 41 patreons:

Goal 1 - 26% - This goal would help us to fully fund the hosting of ForgeBox.io (www.forgebox.io), the ColdFusion software directory.
Goal 2 - 13% - This goal would fund the development of CommandBox CLI, so it can remain FREE and Open Source forever.
Goal 3 - 6% - This goal would help us to fully fund the Modernize or Die podcasts.

https://www.patreon.com/ortussolutions.

News and Announcements

Critical Security Update for ColdFusion APSB23-25

From Adobe

https://community.adobe.com/t5/coldfusion-discussions/released-coldfusion-2021-and-2018-march-2023-security-updates/td-p/13649873

From Foundeo

Adobe has just published a security bulletin APSB23-25, and has released security updates for ColdFusion 2018 and 2021.

We recommend installing these update as soon as possible, because one of the vulnerabilities has been actively exploited by attackers already.

https://helpx.adobe.com/security/products/coldfusion/apsb23-25.html
https://helpx.adobe.com/coldfusion/kb/coldfusion-2018-update-16.html
https://helpx.adobe.com/coldfusion/kb/coldfusion-2021-update-6.html

HackMyCF has been updated to warn you if the hotfix is missing.

It is important to note that if you are on ColdFusion 11, or 2016 that it is possible that your servers could be vulnerable to at least one of these issue as well. However, because these versions reached end of life they are no longer receiving security patches from Adobe.

One thing you can do to mitigate one of these issues is to block requests containing a variable named _cfclient. Some of the filters in FuseGuard may help prevent some attack vectors when configured to. But the best solution is to upgrade to CF2018 or 2021 and apply the patch released today.
--
Foundeo Inc.

ICYMI - Authentication Bypass Vulnerability in Mura CMS and Masa CMS (CVE-2022-47003 and CVE-2022-47002)

Mura CMS is a popular content management system written in ColdFusion/CFML. While it was originally a commercial open source product, it was re-licensed as a closed source application with the release of Mura CMS v10 in 2020. There are forked open source projects based on the last open source release of Mura CMS, including Masa CMS - which is actively maintained.

Multiple versions of Mura CMS and Masa CMS contain an authentication bypass vulnerability that can allow an unauthenticated attacker to login as any Site Member or System User.
https://hoyahaxa.blogspot.com/2023/03/authentication-bypass-mura-masa.html

ICYMI - State of the CF Union 2023 Released

Help us find out the state of the CF Union – what versions of CFML Engine do people use, what frameworks, tools etc.
https://teratech.com/state-of-the-cf-union-2023-survey

New Releases and Updates

ICYMI - CommandBox 5.8.0 Released!

We are pleased to announce the release of CommandBox 5.8.0, which comes with a handful of new features and some important library updates.

Now bundles commandbox-cfconfig, commandbox-dotenv, commandbox-update-check. Automatically installed or updated when you start CLI

Automatically sets the content type in the HTTP response for static file typesl. You can customize in server.json

Config and Module Sync - if you are authenticated to ForgeBox in the CLI, you can synchronize config settings to and from.
Web Server Case Sensitivty - forcing case sensitivity on Windows

REPL improvements

As usual, you can acquire the latest release from our download page or your favorite HomeBrew or apt/yum repo

https://www.ortussolutions.com/products/commandbox#download

https://www.ortussolutions.com/blog/commandbox-580-released

https://commandbox.ortusbooks.com/

ICYMI - First Lucee 6 Beta Released

Remember this is a BETA, so it’s not production ready, what we are looking for in this first BETA release, is for you to try and run your apps / test suites in locally and let us know how it goes for you.

https://dev.lucee.org/t/first-lucee-6-public-beta-is-available-6-0-0-346-beta/12195

Webinar / Meetups and Workshops

Ortus Event Calendar for Google

https://calendar.google.com/calendar/u/0?cid=Y181NjJhMWVmNjFjNGIxZTJlNmQ4OGVkNzg0NTcyOGQ1Njg5N2RkNGJiNjhjMTQwZjc3Mzc2ODk1MmIyOTQyMWVkQGdyb3VwLmNhbGVuZGFyLmdvb2dsZS5jb20

Ortus Webinar - March 17, 2023 - CBSecurity with Luis Majano
Friday, March 17th, at 3pm CST.
Signup Now: https://us02web.zoom.us/meeting/register/tZAsf-6hrzsuE9POBoeyMYsFPY1AN-M2x29F

Ortus Office Hours - Date TBD
Due to spring break, good friday, lots of people at Dev Nexus and CF Summit East, we might pu...

  continue reading

218 jaksoa

Усі епізоди

×
 
Loading …

Tervetuloa Player FM:n!

Player FM skannaa verkkoa löytääkseen korkealaatuisia podcasteja, joista voit nauttia juuri nyt. Se on paras podcast-sovellus ja toimii Androidilla, iPhonela, ja verkossa. Rekisteröidy sykronoidaksesi tilaukset laitteiden välillä.

 

Pikakäyttöopas