Joomla! 3.8.8 released

Announcements from the Joomla! Project for the attention of all Users. We encourage all Joomla! users to subscribe to this forum or check it regularly.
Joomla! Security Updates: http://feeds.joomla.org/JoomlaSecurityNews | Joomla! Vulnerable Extensions: http://feeds.joomla.org/JoomlaSecurityV ... Extensions
Post Reply
User avatar
pe7er
Joomla! Master
Joomla! Master
Posts: 22190
Joined: Thu Aug 18, 2005 8:55 pm
Location: Nijmegen, The Netherlands
Contact:

Joomla! 3.8.8 released

Post by pe7er » Sun May 27, 2018 8:26 pm

Joomla 3.8.8 is now available. This is a security release which addresses 9 security vulnerabilities, contains over 50 bug fixes, and includes various security related improvements.

What's in 3.8.8?
Joomla 3.8.8 addresses 9 security vulnerabilities / hardenings and several bugs, including:

Security Issues Fixed
  • Low Priority - Core - ACL violation in access levels (affecting Joomla 2.5.0 through 3.8.7)
  • Low Priority - Core - Add phar files to the upload blacklist (affecting Joomla 2.5.0 through 3.8.7)
  • Moderate Priority - Core - Information Disclosure about unpublished tags (affecting Joomla 3.1.0 through 3.8.7)
  • Low Priority - Core - Installer leaks plain text password to local user (affecting Joomla 3.0.0 through 3.8.7)
  • Moderate Priority - Core - XSS Vulnerabilities & additional hardening (affecting Joomla 3.0.0 through 3.8.7)
  • Low Priority - Core - Filter field in com_fields allows remote code execution (affecting Joomla 3.7.0 through 3.8.7)
  • Low Priority - Core - Session deletion race condition (affecting Joomla 3.0.0 through 3.8.7)
    Low Priority - Core - Possible XSS attack in the redirect method (affecting Joomla 3.2.1 through 3.8.7)
  • Low Priority - Core - XSS vulnerability in the media manager (affecting Joomla 1.5.0 through 3.8.7)
See announcement for details: https://www.joomla.org/announcements/re ... lease.html

Please see the documentation wiki for the security recommendations for updated sites.
More details about the session deletion race condition are available on the Developer Network site.

Bug fixes and Improvements
  • Miscellaneous accessibility improvements for the Backend
  • Updated CodeMirror to 5.37 and various improvements #20269 #19833 #12542
  • Improved handling of numeric user group names #20091
  • [com_content] Filter by no author #20245
  • Added support for PHP 7.3’s is_countable function #20441
  • Sending passwords by email disabled by default for new installs #20247
Visit GitHub for the full list of bug fixes.

Full announcement + download links
https://www.joomla.org/announcements/re ... lease.html

Discuss here: viewtopic.php?f=9&t=962390
Kind Regards,
Peter Martin, Global Moderator
https://db8.nl - Joomla specialist, Nijmegen, Nederland
Co-developer of d2 Content https://data2site.com/joomla-extensions/d2-content

Post Reply

Return to “Announcements”