Lucee 6.2.9.4-RC available for testing

Lucee 6.2.9.4-RC is available for testing. It is a small fix release on top of 6.2.8.20 with 4 fixes, including two regressions and a security fix in the Administrator.

Download: https://download.lucee.org/

  • Docker: lucee/lucee:6.2.9.4-RC, plus the -light, -zero and -nginx variants (Docker Hub)
  • Maven: org.lucee:lucee:6.2.9.4-RC

Overview

  • Inspect Templates “Auto” works again: since 6.2.8.10, changes to .cfm/.cfc files in web-context mappings were not detected until a restart.
  • Java constructor resolution: an exact parameter type match takes priority again, so for example org.json.JSONObject gets the right constructor.
  • Administrator security fix: the action URL parameter is now encoded, which closes an XSS hole in the admin.
  • Less noise: cfdirectory no longer writes stray debug output, and cfexecute errors now include the underlying cause.

Changelog

Regressions fixed

  • ⭐ LDEV-6482: Inspect Templates “Auto” stopped detecting CFM/CFC changes after LDEV-6358. The inspect ticker is now also started for web-context mappings.
  • ⭐ LDEV-5519: Lucee called the wrong constructor on org.json.JSONObject. Exact type matches take priority again when resolving Java constructors.

Bug fixes

  • ⭐ LDEV-3673 (security): fixed an XSS in the Administrator by encoding the action URL parameter in the admin layout.
  • LDEV-6445: removed stray debug prints in cfdirectory and cfexecute. cfexecute also keeps the original cause when an external process fails to start.

Improvements

  • None. This RC contains fixes only.

Full changelog: https://download.lucee.org/changelog/?version=6.2

Testing

Please give this RC a spin, especially if you use inspectTemplate="auto" or create Java objects with constructor arguments. Report any problems here on the forum or in Jira (LDEV).

2 Likes

Awesome, we’ll start basic smoke tests for these locally today.