Elérhető a Joomla 3.9.25 kiadása. Ez a biztonsági kiadás a Joomla 3.x verziójához készült, 3 biztonsági foltot és számos hibajavítást tartalmaz.
- Megjelenés dátuma: 2021. március 2, kedd
- A hivatalos kiadási jegyzék elérhető itt: https://www.joomla.org/announcements/release-news/5834-joomla-3-9-25.html
Mit tartalmaz a 3.9.25-ös verzió?
A Joomla! 3.9.25-ös verzió 9 biztonsági hibát javít, valamint több mint 40 biztonsági foltot tartalmaz.
Javított biztonsági kérdések
- [20210301] Low Severity - Low Impact - Insecure randomness within 2FA secret generation (affecting Joomla! 3.2.0 through 3.9.24)
- [20210302] Low Severity - Low Impact - Potential Insecure FOFEncryptRandval (affecting Joomla! 3.2.0 through 3.9.24)
- [20210303] Low Severity - Moderate Impact - XSS within alert messages showed to users (affecting Joomla! 2.5.0 through 3.9.24)
- [20210304] Low Severity - Moderate Impact - XSS within the feed parser library (affecting Joomla! 2.5.0 through 3.9.24)
- [20210305] Low Severity - Low Impact - Input validation within the template manager (affecting Joomla! 3.2.0 through 3.9.24)
- [20210306] Low Severity - Moderate Impact - com_media allowed paths that are not intended for image uploads (affecting Joomla! 3.0.0 through 3.9.24)
- [20210307] Low Severity - Moderate Impact - ACL violation within com_content frontend editing (affecting Joomla! 3.0.0 through 3.9.24)
- [20210308] Low Severity - Moderate Impact - Path Traversal within joomla/archive zip class (affecting Joomla! 3.0.0 through 3.9.24)
- [20210309] Low Severity - Moderate Impact - Inadequate filtering of form contents could allow to overwrite the author field (affecting Joomla! 1.6.0 through 3.9.24)
Hibajavítások és fejlesztések
- Fix Save as Copy tag #32454
- Fix published attribute for Tag field #32332
- Fix batch menu items #32380
- Stream transport should enable verify_peer_name when possible #16501
- Optimize the code for rename incorrectly cased files on update #32176
- Addional PHP 8 improvments #31977 #32374
