Security Fix for ColdFusion on Wheels 1.1.x and 1.0.x Released
December 14, 2011
Posted in Releases
Posted By: Tony Petruzzi
A security vulnerability has been identified in both the 1.1.x and 1.0.x versions of Wheels. In response, the Wheels team is releasing patches for both the current and legacy versions. Version 1.1.7 is to address current version and version 1.0.6 is to address legacy versions.
At this time, we encourage all users of the framework to upgrade as soon as possible. These new versions contain only the patches necessary to close the security vulnerability. No new bug fixes or enhancement features are contained.
The Wheels team would like to thank Pete Freitag of <a href="http://foundeo.com/">foundeo.com</a> for reporting and helping to patch the security vulnerability.
<a href="https://cfwheels.org/download" target="_blank">Download versions 1.1.7 and 1.0.6</a>
D
daniel
Is it enough to overwrite the wheels folder when you're upgrading from 1.16? Or do other files need to be updated as well?
Dec 20, 2011
P
Tony Petruzzi
yes. you can just overwrite the wheels folder.
Dec 22, 2011
Please login to join the conversation! Login