Vulnerability Assessment Remediation Suggtions

Discussion regarding Joomla! 3.x security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Locked
dudedowne
Joomla! Apprentice
Joomla! Apprentice
Posts: 25
Joined: Wed Oct 21, 2020 6:24 pm

Vulnerability Assessment Remediation Suggtions

Post by dudedowne » Wed Dec 15, 2021 2:57 am

Hello All,
Another Joomla newb here seeking advice. Our network team recently ran a preliminary SecuMetr vulnerability assessment and found the following on our Joomla 3.10.3 implementation. I know that 3.10.4 just was released and we are currently testing J4 compatibility but are not quite ready to move there yet.

Here are the detected vulnerabilities. I was able to find solutions for the ones that are crossed out. However, the other items didn't seem to yield any applicable workarounds.
vulnerabilities.png
CGI Generic Command Execution (time-based)
JQuery 1.2 < 3.5.0 Multiple XSS
JQuery < 3.4.0 Object Prototype Pollution Vulnerability
JQuery < 3.0.0 XSS

Thanks again for any advice,
DD
You do not have the required permissions to view the files attached to this post.

User avatar
pmleconte
Joomla! Guru
Joomla! Guru
Posts: 591
Joined: Fri Mar 17, 2017 12:55 pm
Location: France

Re: Vulnerability Assessment Remediation Suggtions

Post by pmleconte » Wed Dec 15, 2021 6:48 am

Hi,

If you take a look at media/jui/js/jquery.js, just read the top lines and you'll see that this has been fixed by Joomla team at least 2 years ago.

I wrote "2 years ago" by looking https://github.com/joomla/joomla-cms/tr ... dia/jui/js which gives you the last update date for jquery.js.

Pascal
If anything can go wrong, it will.
https://www.conseilgouz.com/en

dudedowne
Joomla! Apprentice
Joomla! Apprentice
Posts: 25
Joined: Wed Oct 21, 2020 6:24 pm

Re: Vulnerability Assessment Remediation Suggtions

Post by dudedowne » Thu Dec 16, 2021 1:59 am

pmleconte,

Thanks for the reply. I am assuming it is a false positive, but not sure how to verify. The tool definitely shows juquery.min.js reporting version 1.12.4 and not the current version of 3.5.0. Is this expected?

Much appreciated!
DD

User avatar
brian
Joomla! Master
Joomla! Master
Posts: 12787
Joined: Fri Aug 12, 2005 7:19 am
Location: Leeds, UK
Contact:

Re: Vulnerability Assessment Remediation Suggtions

Post by brian » Thu Dec 16, 2021 8:19 am

You can check by reading the file and seeing the comment at the top of the file
"Exploited yesterday... Hacked tomorrow"
Blog http://brian.teeman.net/
Joomla Hidden Secrets http://hiddenjoomlasecrets.com/


Locked

Return to “Security in Joomla! 3.x”