Lucee 6.2.9.4-RC is available for testing. It is a small fix release on top of 6.2.8.20 with 4 fixes, including two regressions and a security fix in the Administrator.
Download: https://download.lucee.org/
- Docker:
lucee/lucee:6.2.9.4-RC, plus the-light,-zeroand-nginxvariants (Docker Hub) - Maven:
org.lucee:lucee:6.2.9.4-RC
Overview
- Inspect Templates “Auto” works again: since 6.2.8.10, changes to .cfm/.cfc files in web-context mappings were not detected until a restart.
- Java constructor resolution: an exact parameter type match takes priority again, so for example
org.json.JSONObjectgets the right constructor. - Administrator security fix: the
actionURL parameter is now encoded, which closes an XSS hole in the admin. - Less noise: cfdirectory no longer writes stray debug output, and cfexecute errors now include the underlying cause.
Changelog
Regressions fixed
- â LDEV-6482: Inspect Templates “Auto” stopped detecting CFM/CFC changes after LDEV-6358. The inspect ticker is now also started for web-context mappings.
- â LDEV-5519: Lucee called the wrong constructor on
org.json.JSONObject. Exact type matches take priority again when resolving Java constructors.
Bug fixes
- â LDEV-3673 (security): fixed an XSS in the Administrator by encoding the
actionURL parameter in the admin layout. - LDEV-6445: removed stray debug prints in cfdirectory and cfexecute. cfexecute also keeps the original cause when an external process fails to start.
Improvements
- None. This RC contains fixes only.
Full changelog: https://download.lucee.org/changelog/?version=6.2
Testing
Please give this RC a spin, especially if you use inspectTemplate="auto" or create Java objects with constructor arguments. Report any problems here on the forum or in Jira (LDEV).