Joomla! 3.9.23 released

Announcements from the Joomla! Project for the attention of all Users. We encourage all Joomla! users to subscribe to this forum or check it regularly.
Joomla! Security Updates: https://developer.joomla.org/security-c ... d?type=rss | Joomla! Vulnerable Extensions: https://extensions.joomla.org/vulnerabl ... json-feed/
Locked
User avatar
pe7er
Joomla! Master
Joomla! Master
Posts: 24985
Joined: Thu Aug 18, 2005 8:55 pm
Location: Nijmegen, Netherlands
Contact:

Joomla! 3.9.23 released

Post by pe7er » Tue Nov 24, 2020 4:30 pm

Joomla 3.9.23 is now available. This is a security release for the 3.x series of Joomla which addresses 7 security vulnerabilities and contains more than 35 bug fixes and improvements.

What's in 3.9.23?
Joomla 3.9.23 includes 7 security vulnerability fixes and addresses several bugs, including:

Security Issues Fixed
  • [20201101] Low Priority - High Impact - Write ACL violation in multiple core views (affecting Joomla! 2.5.0 through 3.9.22) More information »
  • [20201102] Low Priority - Moderate Impact - Disclosure of secrets in Global Configuration page (affecting Joomla! 2.5.0 through 3.9.22) More information »
  • [20201103] Low Priority - Moderate Impact - Path traversal in mod_random_image (affecting Joomla! 2.5.0 through 3.9.22) More information »
  • [20201104] Low Priority - High Impact - SQL injection in com_users list view (affecting Joomla! 3.0.0 through 3.9.22) More information »
  • [20201105] Low Priority - Low Impact - User Enumeration in backend login (affecting Joomla! 3.9.0 through 3.9.22) More information »
  • [20201106] Low Priority - Low Impact - CSRF in com_privacy emailexport feature (affecting Joomla! 3.9.0 through 3.9.22) More information »
  • [20201107] Low Priority - High Impact - Write ACL violation in multiple core views (affecting Joomla! 1.7.0 through 3.9.22) More information »
Bug fixes and Improvements
In order to get Joomla ready for PHP 8 (to be released on November 26th, 2020), Joomla 3.9.23 includes fixes to ensure PHP 8 compatibility (see #31246, #30608, #30582, #29353, #30922, #31444, #31434, #31442, #31445).
  • TinyMCE updated #30329
  • Fix for frontend module editing permissions #30778
  • Fix for the lost of transparency when cropping/resizing images #30977
  • Validation rule added for the redirect header field #31016
Visit GitHub for the full list of bug fixes.

Download
Full announcement + download links: https://www.joomla.org/announcements/re ... -9-23.html

Discussion Forum: viewtopic.php?f=9&t=983197
Kind Regards,
Peter Martin, Global Moderator
Company website: https://db8.nl/en/ - Joomla specialist, Nijmegen, Netherlands
The best website: https://the-best-website.com

Locked

Return to “Announcements”