News Feed Category

Joomla! Security News

    • Project: Joomla!
    • SubProject: CMS
    • Severity: Low
    • Versions: 3.7.0 through 3.8.1
    • Exploit type: Information Disclosure
    • Reported Date: 2017-May-17
    • Fixed Date: 2017-November-07
    • CVE Number: CVE-2017-16633

    Description

    A logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.

    Affected Installs

    Joomla! CMS versions 3.7.0 through 3.8.1

    Solution

    Upgrade to version 3.8.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By: Internal JSST audit
    • Project: Joomla!
    • SubProject: CMS
    • Severity: Medium
    • Versions: 3.2.0 through 3.8.1
    • Exploit type: 
    • Reported Date: 2017-October-31
    • Fixed Date: 2017-November-07
    • CVE Number: CVE-2017-16634

    Description

    A bug allowed third parties to bypass a user's 2-factor-authentication method.

    Affected Installs

    Joomla! CMS versions 3.2.0 through 3.8.1

    Solution

    Upgrade to version 3.8.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:Yarince
    • Project: Joomla!
    • SubProject: CMS
    • Severity: Medium
    • Versions: 1.5.0 through 3.8.1
    • Exploit type: Information Disclosure
    • Reported Date: 2017-October-06
    • Fixed Date: 2017-November-07
    • CVE Number: CVE-2017-14596

    Description

    Inadequate escaping in the LDAP authentication plugin can result in disclosure of username and password.

    Affected Installs

    Joomla! CMS versions 1.5.0 through 3.8.1

    Solution

    Upgrade to version 3.8.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:Dr. Johannes Dahse, RIPS Technologies GmbH
    • Project: Joomla!
    • SubProject: CMS
    • Severity: Low
    • Versions: 3.7.0 through 3.7.5
    • Exploit type: Information Disclosure
    • Reported Date: 2017-August-4
    • Fixed Date: 2017-September-19
    • CVE Number: CVE-2017-14595

    Description

    A logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.

    Affected Installs

    Joomla! CMS versions 3.7.0 through 3.7.5

    Solution

    Upgrade to version 3.8.0

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:Michal Prochaczek
    • Project: Joomla!
    • SubProject: CMS
    • Severity: Medium
    • Versions: 1.5.0 through 3.7.5
    • Exploit type: Information Disclosure
    • Reported Date: 2017-July-27
    • Fixed Date: 2017-September-19
    • CVE Number: CVE-2017-14596

    Description

    Inadequate escaping in the LDAP authentication plugin can result into a disclosure of username and password.

    Affected Installs

    Joomla! CMS versions 1.5.0 through 3.7.5

    Solution

    Upgrade to version 3.8.0

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:Dr. Johannes Dahse, RIPS Technologies GmbH

About Helix

The Arizona Bar Foundation was created by the State Bar of Arizona as a separate 501(c) 3 organization in 1978, charging it with the mission of promoting access to justice for all Arizonans. The Foundation strives to fulfill this mission by preparing Arizona youth for civic responsibility and providing access to justice for Arizonan's most in need. Through the provision of technical and financial assistance to probation & resource officers, teachers & administrators, private attorneys & judges, and legal service attorneys & advocates, the Foundation works to level the playing field, so that all in Arizona have knowledge and access to the justice systems. To find out more about the programs of the Arizona Foundation for Legal Services & Education, visit the Law Related Education, Legal Services or IOLTA areas of this website.

 

Latest News

04 August 2017
14 August 2015