Modernize or Die® - CFML News for December 28th, 2021 - Episode 129 episode artwork

EPISODE · Dec 28, 2021 · 39 MIN

Modernize or Die® - CFML News for December 28th, 2021 - Episode 129

from Modernize or Die ® Podcast · host Ortus Solutions

2021-12-28 Weekly News - Episode 129Watch the video version on YouTube at https://youtu.be/xQ44rxXK_Z0 Hosts: Gavin Pickin - Senior Software Developer for Ortus SolutionsDaniel Garcia  - Senior Software Developer for Ortus SolutionsThanks to our Sponsor - Ortus SolutionsThe makers of ColdBox, CommandBox, ForgeBox, TestBox and almost every other Box out there. A few ways  to say thanks back to Ortus Solutions:Like and subscribe to our videos on YouTube. Subscribe to our Podcast on your Podcast Apps and leave us a reviewSign up for a free or paid account on CFCasts, which is releasing new content every weekBuy Ortus’s Book - 102 ColdBox HMVC Quick Tips and Tricks on GumRoad (http://gum.co/coldbox-tips)Patreon SupportWe have 37 patreons providing 97% of the funding for our Modernize or Die Podcasts via our Patreon site: https://www.patreon.com/ortussolutions. News and EventsLog4j Vulnerability UpdatesOrtus has updated the Adobe CF engines on ForgeBox for CommandBox users to include the latest security patches released from Adobe the same day Adobe released them.2021.0.3+3297792018.0.13+329786Please update any CommandBox servers immediately to use these new, secure versions of ACF. #CFML #ColdFusionTweet from BradApache announced today that the formatMsgNoLookups JVM arg is no longer considered sufficient to mitigate a vuln ver of Log4j.  https://logging.apache.org/log4j/2.x/security.html Their advice (and Adobe's) is to completely remove the JndiLookup class file from the log4j-core jar or update to 2.16. #CFMLNew Blog PostsAdobe Updates ReleasesWe are pleased to announce that we have released the updates for the following ColdFusion versions:ColdFusion (2021 release) Update 3ColdFusion (2018 release) Update 13ColdFusion 2021 Performance Monitoring Toolset Update 3ColdFusion 2018 Performance Monitoring Toolset Update 4ColdFusion API Manager updateshttps://coldfusion.adobe.com/2021/12/update-coldfusion-security-updates-log4j-vulnerability/ If you have applied the #ColdFusion updates from Fri, Dec 17, Adobe now says it's ok to copy in the log4j 2.17 jars, and they even offer just what you need. This is NOT the way to mitigate INSTEAD of doing the updates.https://helpx.adobe.com/coldfusion/kb/log4j-2-16-vulnerability-coldfusion.htmlPrevious Blog PostsAdobe’s update on the matter (thanks charlie for pointing this out)Blog - https://coldfusion.adobe.com/2021/12/update-log4j-vulnerability/ Update - https://helpx.adobe.com/coldfusion/kb/log4j-vulnerability-coldfusion.html Lucee is not affected https://dev.lucee.org/t/lucee-is-not-affected-by-the-log4j-jndi-exploit-cve-2021-44228/9331 Charlie’s Blog on the matter https://www.carehart.org/blog/2021/12/14/about_the_log4jshell_pandemic https://coldfusion.adobe.com/2021/12/dealing-recent-log4j-vulnerability-adobe-releases-update/ More news links about Log4j https://www.zdnet.com/article/log4j-flaw-attackers-are-making-thousands-of-attempts-to-exploit-this-severe-vulnerability/Adobe WorkshopsMore Adobe #ColdFusion Workshops announced, lead by Damien Bruyndonckx (Brew-en-dohnx)2 dates announced:February 2, 20229.00 AM - 4.30 PM CET1.30 PM - 9.00 PM ISTMarch 09, 20229.00 AM - 4.30 PM CET1.30 PM - 9.00 PM ISThttps://cf-workshop.meetus.adobeevents.com/ ICYMI - CBSecurity V2.15.0 released🚀 AddedPass custom claims from refreshToken( token, customClaims) method when refreshing tokensPass in the current jwt payload in to getJWTCustomClaims( payload )The auto refresh token features now will auto refresh not only on expired tokens, but on invalid and missing tokens as well. Thanks to @elpete🐛 FixedTimeout in token storage is now the token timeouthttps://www.forgebox.io/view/cbsecurity ICYMI - Spreadsheet-CFML 3.2.3 released with log4j-2.17.0Spreadsheet-CFML 3.2.3 released with log4j-2.17.0 Seems none of these updates are strictly necessary as POI doesn't use the "core" jar, but putting them out as a precaution. #cfmlhttps://www.forgebox.io/view/spreadsheet-cfmlCFCasts Content Updateshttps://www.cfcasts.com Just ReleasedModernize Or Die Podcast SoapBox Edition with Luis MajanoColdBox Anniversary Edition with Jon ClausenOrtus Single Video SeriesCSS Animation Using TransformComing soonInto the Box LATAMSend your suggestions at https://cfcasts.com/supportConferences and TrainingVueJS Nation ConferenceOnline Live EventJanuary 26th & 27th 2022Register for FreeCall for Speakers is open until Dec 31 2021https://vuejsnation.com/ More conferencesNeed more conferences, this site has a huge list of conferences for almost any language/community.https://confs.tech/Blogs, Tweets and Videos of the WeekTweet - James Moberg -Log4j Detection Library Apart from updating the Log4j library, I haven't seen any #ColdFusion detection libraries yet. Here's my first attempt at detecting & blocking exploit attempts.https://dev.to/gamesover/log4j-exploit-pattern-detection-using-coldfusioncfml-4l17 #cfmlhttps://twitter.com/gamesover/status/1473418402840838144https://twitter.com/gamesoverTweet - Brad Wood - Fusion Reactor transaction names for non coldbox appsFor non-ColdBox apps that route multiple pages through a "front controller" like index.cfm, I've published a demo showing how to customize the transaction name @Fusion_Reactor reports for each page using the FRAPI SDKhttps://github.com/bdw429s/FRAPI-transaction-name-demo #CFML #ColdFusionBlog - Adobe - UPDATE: ColdFusion security updates for Log4j vulnerabilityWe are pleased to announce that we have rel...

Gavin Pickin and Daniel Garcia hosts the last CFML News Podcast of the year. They talked about the big news in the CFML World, the Log4j java library with a zero day vulnerability... and all of the developments and updates released since then. They discuss the latest CFCasts content, and some upcoming conferences. They spotlight a lot of great blog posts, tweets, videos and podcasts, too many to list, so listen to the show. They announce some jobs from getCfmlJobs.com They show off the ForgeBox module of the Week - commandbox-cflint - This is a CommandBox module for linting your CFML code using CFLint. CFLint Version: 1.4.1 This week's VS Code Tip of the week is Code Time - Code Time is an open source plugin for automatic programming metrics and time tracking in Visual Studio Code. Join our community of over 200,000 developers who use Code Time to reclaim time for focused, uninterrupted coding. Protect valuable code time and stay in flow. They thanked all their Patreons - they talked a little information about perks for their Patreon supporters, and a new option, Annual Memberships with a discount. For the show notes - visit the website https://cfmlnews.modernizeordie.io/episodes/modernize-or-die-cfml-news-for-december-28th-2021-episode-129 Music from this podcast used under Royalty Free license from SoundDotCom https://www.soundotcom.com/ and BlueTreeAudio https://bluetreeaudio.com

NOW PLAYING

Modernize or Die® - CFML News for December 28th, 2021 - Episode 129

0:00 39:14

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

French Your Way Jessica: Native French teacher founder of French Your Way Boost your French listening skills and test your comprehension with this one of a kind series of podcasts. Get the chance to listen to a real conversation between native speakers talking at normal speed AND customise your learning experience through carefully designed sets of questions (2 levels of difficulty) available for download at www.frenchvoicespodcast.com. All interviews also come with the transcript. French teacher Jessica interviews native speakers of French from around the world who share a bit of their life and passion. Where else would you meet in one same place a French yoga teacher based in Melbourne, a soap manufacturer from Provence, or a couple cycling around the world? That Hoarder: Overcome Compulsive Hoarding That Hoarder Hoarding disorder is stigmatised and people who hoard feel vast amounts of shame. This podcast began life as an audio diary, an anonymous outlet for somebody with this weird condition. That Hoarder speaks about her experiences living with compulsive hoarding, she interviews therapists, academics, researchers, children of hoarders, professional organisers and influencers, and she shares insight and tips for others with the problem. Listened to by people who hoard as well as those who love them and those who work with them, Overcome Compulsive Hoarding with That Hoarder aims to shatter the stigma, share the truth and speak openly and honestly to improve lives. Flottengeflüster ALD Automotive Österreich | LeasePlan Beim Flottengeflüster powered by ALD Automotive | LeasePlan präsentieren Jörg Janik und Peter Gutenbrunner alle zwei Wochen spannende Informationen rund um das Thema nachhaltige Mobilität. Beide beschäftigen sich schon lange mit der Thematik und bringen umfangreiches Fachwissen mit. Sollten sie aber doch einmal nicht weiter wissen, werden unsere Expert*innen hinzugezogen, die ihnen gerne mit Rat und Tat zur Seite stehen. The Small Business Startup School – Business Notes | Financial Literacy | Retail Psychology – For Professionals & Entrepreneurs The Small Business Startup School Inc. Starting or buying a small business? While personal circumstances may vary, business patterns remain timeless. On The Small Business Startup School, we explore strategies, insights, and practical solutions to help entrepreneurs confidently navigate their journey.Hosted by Ola Williams—a retail entrepreneur, fintech founder, and financial coach with over two decades of experience—this podcast marries financial awareness and retail psychology with optimism to deliver actionable takeaways.Join us to learn, grow, and connect as we uncover the keys to business success.Let’s continue to learn together and be encouraged to keep on connecting!

Frequently Asked Questions

How long is this episode of Modernize or Die ® Podcast?

This episode is 39 minutes long.

When was this Modernize or Die ® Podcast episode published?

This episode was published on December 28, 2021.

What is this episode about?

2021-12-28 Weekly News - Episode 129Watch the video version on YouTube at https://youtu.be/xQ44rxXK_Z0 Hosts: Gavin Pickin - Senior Software Developer for Ortus SolutionsDaniel Garcia  - Senior Software Developer for Ortus SolutionsThanks to our...

Can I download this Modernize or Die ® Podcast episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!