Joomla! 3.9.20 released

Announcements from the Joomla! Project for the attention of all Users. We encourage all Joomla! users to subscribe to this forum or check it regularly.
Joomla! Security Updates: https://developer.joomla.org/security-c ... d?type=rss | Joomla! Vulnerable Extensions: https://extensions.joomla.org/vulnerabl ... json-feed/
Locked
User avatar
pe7er
Joomla! Master
Joomla! Master
Posts: 24986
Joined: Thu Aug 18, 2005 8:55 pm
Location: Nijmegen, Netherlands
Contact:

Joomla! 3.9.20 released

Post by pe7er » Tue Jul 14, 2020 4:16 pm

Joomla 3.9.20 is now available. This is a security release for the 3.x series of Joomla which addresses 6 security vulnerabilities and contains over 25 bug fixes and improvements.

What's in 3.9.20?
Joomla 3.9.20 includes 6 security vulnerability fixes and addresses several bugs, including:

Security Issues Fixed
  • Low Priority - Core - CSRF in com_installer ajax_install endpoint (affecting Joomla! 3.7.0 through 3.9.19) More information »
  • Moderate Priority - Core - Missing checks can lead to a broken usergroups table record (affecting Joomla! 2.5.0 through 3.9.19) More information »
  • Low Priority - Core - CSRF in com_privacy remove-request feature (affecting Joomla! 3.9.0 through 3.9.19) More information »
  • Low Priority - Core - Variable tampering via user table class (affecting Joomla! 3.0.0 through 3.9.19) More information »
  • Low Priority - Core - Escape mod_random_image link (affecting Joomla! 3.0.0 through 3.9.19) More information »
  • Low Priority - Core - System Information screen could expose redis or proxy credentials (affecting Joomla! 3.0.0 through 3.9.19) More information »
Bug fixes and Improvements
  • Upload & Update tab of Joomla Update Component: Fix to allow upload of ZIP filetype only #29877
  • Local database server: Allow optional port numbers #29567
  • Beez3 Template: Markup fix for the Tabs layout of com_contact #29636
  • Beez3 Template: Allow custom field editing on frontend #29577
  • Backend cache cleared when purging updates #29603
Visit GitHub for the full list of bug fixes.

Download
Full announcement + download links: https://www.joomla.org/announcements/re ... -9-20.html

Discussion Forum: viewtopic.php?f=9&t=981066
Kind Regards,
Peter Martin, Global Moderator
Company website: https://db8.nl/en/ - Joomla specialist, Nijmegen, Netherlands
The best website: https://the-best-website.com

Locked

Return to “Announcements”