Big update for ColdFusion 10, and Security Fix

We just released update 11 for ColdFusion 10. Details here: ColdFusion 10 Update 11. Quite an impressive list of fixes. This also includes a security fix for the web sockets thing that Adam Cameron found a few days ago. (Correction - Adam blogged about it, but Henry Ho found it. Sorry Henry!) For folks running ColdFusion 9, there is a separate security hot fix you should deploy.

Archived Comments

Comment 1 by John Bliss posted on 7/9/2013 at 9:57 PM

Ray, this one still seems to be outstanding...what's the best way for me to find out when it might be fixed?

https://bugbase.adobe.com/i...

Comment 2 by Raymond Camden posted on 7/9/2013 at 10:02 PM

As far as I know - by calling support.

Comment 3 by Rick H posted on 7/9/2013 at 11:29 PM

Does Adobe have a ColdFusion security notice newsletter? Would be useful (although you also perform that service).

THanks...Rick..

Comment 4 by Raymond Camden posted on 7/9/2013 at 11:32 PM

Yes, go here http://www.adobe.com/suppor... and click notification services.

Comment 5 by Adam Cameron posted on 7/10/2013 at 1:03 AM

Hey, it was Henry Ho that discovered the web sockets thing. I just did some research into it.

--
Adam

Comment 6 by Raymond Camden posted on 7/10/2013 at 1:04 AM

Ah, thanks for the correction. Editing the post.