Joomla! 3.9.25 released

Announcements from the Joomla! Project for the attention of all Users. We encourage all Joomla! users to subscribe to this forum or check it regularly.
Joomla! Security Updates: https://developer.joomla.org/security-c ... d?type=rss | Joomla! Vulnerable Extensions: https://extensions.joomla.org/vulnerabl ... json-feed/
Locked
User avatar
pe7er
Joomla! Master
Joomla! Master
Posts: 24974
Joined: Thu Aug 18, 2005 8:55 pm
Location: Nijmegen, Netherlands
Contact:

Joomla! 3.9.25 released

Post by pe7er » Tue Mar 02, 2021 3:31 pm

Joomla 3.9.25 is now available. This is a security release for the 3.x series of Joomla which addresses 9 security vulnerabilities and contains more than 40 bug fixes and improvements.

What's in 3.9.25?
Joomla 3.9.25 includes 9 security vulnerability fixes and addresses several bugs, including:

Security Issues Fixed
  • [20210301] Low Severity - Low Impact - Insecure randomness within 2FA secret generation (affecting Joomla! 3.2.0 through 3.9.24) More information »
  • [20210302] Low Severity - Low Impact - Potential Insecure FOFEncryptRandval (affecting Joomla! 3.2.0 through 3.9.24) More information »
  • [20210303] Low Severity - Moderate Impact - XSS within alert messages showed to users (affecting Joomla! 2.5.0 through 3.9.24) More information »
  • [20210304] Low Severity - Moderate Impact - XSS within the feed parser library (affecting Joomla! 2.5.0 through 3.9.24) More information »
  • [20210305] Low Severity - Low Impact - Input validation within the template manager (affecting Joomla! 3.2.0 through 3.9.24) More information »
  • [20210306] Low Severity - Moderate Impact - com_media allowed paths that are not intended for image uploads (affecting Joomla! 3.0.0 through 3.9.24) More information »
  • [20210307] Low Severity - Moderate Impact - ACL violation within com_content frontend editing (affecting Joomla! 3.0.0 through 3.9.24) More information »
  • [20210308] Low Severity - Moderate Impact - Path Traversal within joomla/archive zip class (affecting Joomla! 3.0.0 through 3.9.24) More information »
  • [20210309] Low Severity - Moderate Impact - Inadequate filtering of form contents could allow to overwrite the author field (affecting Joomla! 1.6.0 through 3.9.24) More information »
Bug fixes and Improvements
  • Fix Save as Copy tag #32454
  • Fix published attribute for Tag field #32332
  • Fix batch menu items #32380
  • Stream transport should enable verify_peer_name when possible #16501
  • Optimize the code for rename incorrectly cased files on update #32176
  • Addional PHP 8 improvments #31977 #32374
Visit GitHub for the full list of bug fixes.

Download
Full announcement + download links: https://www.joomla.org/announcements/re ... -9-25.html

Discussion Forum: viewtopic.php?f=9&t=985110
Last edited by toivo on Tue Mar 02, 2021 10:43 pm, edited 1 time in total.
Reason: mod note: fixed link to bug fixes
Kind Regards,
Peter Martin, Global Moderator
Company website: https://db8.nl/en/ - Joomla specialist, Nijmegen, Netherlands
The best website: https://the-best-website.com

Locked

Return to “Announcements”