displaying top 100 results
Tracker Comment Comment on Code Analyzer False Negative by CFwatson U.
2673450 CF-4126537 CFwatson U. Added By: PreRelease User User Name:Jason Dean Note Added: Entered Bug. Date Added :2015-10-26 20:57:46.0
Tracker Issue Bug 86913:Enhancement request for ESAPI integration
2615162 CF-3043828 Security : General Jason Dean Bug 86913:Enhancement request for ESAPI integration Problem:
Enhancement request for ESAPI integration. Might it ever be needed to have the functions cananocalize() exposed as a CF helper function?
Method:
Result
Tracker Issue Code Analyzer False Negative
2673450 CF-4126537 Security Analyzer Jason Dean Code Analyzer False Negative Problem Description:
This code should be flagged for SQLi, it is not.
component {
public function getUserByID( numeric id ) {
var q = new Query
2682274 CFB-4130093 Installer Jason Dean Will not install Blizzard into directory with a space in it Problem Description: When installing Blizzard Alpha it defaults to installing the application into c:\Blizzard. When I try to change it to c:\Program Files\Blizzard, it errors and tells me it cannot
Tracker Comment Comment on Will not install Blizzard into directory with a space in it by CFwatson U.
2682274 CFB-4130093 CFwatson U. Added By: PreRelease User User Name:Jason Dean Note Added: Windows 10 Enterprise - x64 - US English fresh install, fully updated, no other software installed. Date Added :2015-09-18 20:07:19.0
Tracker Issue Bug 86912:This is an enhancement request for the ESAPI integration and encoding methods
2615163 CF-3043827 Security : General Jason Dean Bug 86912:This is an enhancement request for the ESAPI integration and encoding methods Problem:
This is an enhancement request for the ESAPI integration and encoding methods. One of the things canonicalize() does in the ESAPI is to allow
2615354 CF-3043479 Language Jason Dean Bug 86524:The jBCrypt Library is a tool for makign password hashing more secure an more "future-proof" to the increase speed of hardware that will make brute forcing hashes easier Problem:
The jBCrypt Library is a tool for makign password hashing more secure
2615577 CF-3043161 Security : General Jason Dean Bug 85964:Having the ability to send encrypted email from ColdFusion programatically would be a hugely helpful enterprise feature and would help DoD and other government customers get the security features they Problem:
Having the ability to send
Tracker Issue Bug 85430:A user on Twitter pointed out to me that cfinvoke does NOT support client certificates for web services calls
2615643 CF-3042997 Web Services : General Jason Dean Bug 85430:A user on Twitter pointed out to me that cfinvoke does NOT support client certificates for web services calls Problem:
A user on Twitter pointed out to me that cfinvoke does NOT support client certificates for web services calls
2597699 CF-3042908 General Server Jason Dean Bug 85266:(Watson Migration Closure)CFLDAP does not seem to have the right working for doing some things with Microsoft AD LDAP Problem:
CFLDAP does not seem to have the right working for doing some things with Microsoft AD LDAP. The issues I have
2599077 CF-3040612 Core Runtime : Session Management Jason Dean Bug 81187:When using the HTTPOnly flag in CFCOOKIE on a CF9 Web Application deployed on Tomcat 6, the cookie statement is improperly constructed resulting in appending the HTTPOnly statement to the cookie value Problem:
When using
2599196 CF-3040479 Flex/Flash : AIR Integration Jason Dean Bug 80895:If the SQLite lite DB is encrypted but the cache DB is not, then there is an obvious flaw in the encryption usage because the data will be store unencrypted right next to the encrytped DB on the file Problem:
If the SQLite lite
2682267 CFB-4130100 CFwatson U. Added By: PreRelease User User Name:Jason Dean Note Added: So you worked for three hours without saving your file and when you lost that work it is because CFBuilder is lacking?
I can think of many, many more important features than one that will save you from
2615577 CF-3043161 Kunal S. Bug History
Timestamp|name|field|from value|to value|
21 Jan 2011 02:46:21 GMT | System System | Class Type | | Enhancement |
21 Jan 2011 02:46:21 GMT | System System | Severity | | 8-Not Applicable |
21 Jan 2011 02:47:23 GMT | Jason Dean | Bug Submitted
Tracker Comment Comment on Security Code Analyzer reports false positives for upload code, and repeats warnings/errors by CFwatson U.
, logged a different bug for the same.
Thanks! Date Added :2015-12-22 12:35:37.0
Added By: PreRelease User User Name:Jason Dean Note Added: I would love to get a copy of the attachment for this ticket to try things out. Date Added :2015-10-26 20:28:28.0
Added By: PreRelease User User Name:A. Bakia Note
2597641 CF-3043069 Security : General Jason Dean Bug 85815:There seems to be a problem with the RSA BSafe CryptoJ Library included in ColdFusion enterprise and ColdFusion developer edition that prevents it from working with certain SSL Certificates Problem:
There seems to be a problem with the RSA