Discuss Joomla! 3.9.25
- pe7er
- Joomla! Master
- Posts: 24974
- Joined: Thu Aug 18, 2005 8:55 pm
- Location: Nijmegen, Netherlands
- Contact:
Discuss Joomla! 3.9.25
Here you can discuss about the release of Joomla 3.9.25
See Announcement: viewtopic.php?f=8&t=985109
See Announcement: viewtopic.php?f=8&t=985109
Kind Regards,
Peter Martin, Global Moderator
Company website: https://db8.nl/en/ - Joomla specialist, Nijmegen, Netherlands
The best website: https://the-best-website.com
Peter Martin, Global Moderator
Company website: https://db8.nl/en/ - Joomla specialist, Nijmegen, Netherlands
The best website: https://the-best-website.com
- toivo
- Joomla! Master
- Posts: 17427
- Joined: Thu Feb 15, 2007 5:48 am
- Location: Sydney, Australia
Re: Discuss Joomla! 3.9.25
Localhost test sites and remote sites updated smoothly, as usual. Kudos to the teams and individuals behind this update !
Toivo Talikka, Global Moderator
- PhilTaylor-Prazgod
- Joomla! Ace
- Posts: 1402
- Joined: Sat Aug 20, 2005 12:32 pm
- Location: Jersey, Channel Islands
- Contact:
Re: Discuss Joomla! 3.9.25
For balance, readers should also read https://www.akeeba.com/static-content/5 ... nyway.html which provides insight on two of the reported "vulnerabilities" fixed in this release.
Phil Taylor
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/
- leolam
- Joomla! Master
- Posts: 20652
- Joined: Mon Aug 29, 2005 10:17 am
- Location: Netherlands/ Germany/ S'pore/Bogor/ North America
- Contact:
Re: Discuss Joomla! 3.9.25
@PhilTaylor +1
Leo
Leo
Joomla's #1 Professional Services Provider:
#Joomla Professional Support: https://gws-desk.com -
#Joomla Specialized Hosting Solutions: https://gws-host.com -
#Joomla Professional Support: https://gws-desk.com -
#Joomla Specialized Hosting Solutions: https://gws-host.com -
-
- Joomla! Champion
- Posts: 5932
- Joined: Tue Aug 23, 2005 1:56 pm
- Location: South coast, UK
- Contact:
Re: Discuss Joomla! 3.9.25
Yes @Phil Taylor that is an interesting read on Security.
https://gadsolutions.biz Electrical services
https://electrical-testing-safety.co.uk Testing services
https://electrical-testing-safety.co.uk Testing services
- darb
- Joomla! Hero
- Posts: 2042
- Joined: Thu Jul 06, 2006 12:57 pm
- Location: Stockholm Sweden
- PhilTaylor-Prazgod
- Joomla! Ace
- Posts: 1402
- Joined: Sat Aug 20, 2005 12:32 pm
- Location: Jersey, Channel Islands
- Contact:
Re: Discuss Joomla! 3.9.25
Also [3.9.25] breaks folder name validation because it assumes all folders must start with a-zA-Z
https://github.com/joomla/joomla-cms/issues/32567
https://github.com/joomla/joomla-cms/issues/32567
Phil Taylor
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/
- Maradona
- Joomla! Enthusiast
- Posts: 154
- Joined: Fri Aug 30, 2013 2:08 pm
- Location: Argentina
Re: Discuss Joomla! 3.9.25
Hi,
Wrong link in 'Additional Information' under Joomla Update.
Thanks
Wrong link in 'Additional Information' under Joomla Update.
Thanks
- toivo
- Joomla! Master
- Posts: 17427
- Joined: Thu Feb 15, 2007 5:48 am
- Location: Sydney, Australia
Re: Discuss Joomla! 3.9.25
Thank you for reporting this. It has now been fixed.
Toivo Talikka, Global Moderator
-
- Joomla! Explorer
- Posts: 289
- Joined: Thu Jun 10, 2010 12:38 pm
- Contact:
Re: Discuss Joomla! 3.9.25
@PhilTaylor +1
- Maradona
- Joomla! Enthusiast
- Posts: 154
- Joined: Fri Aug 30, 2013 2:08 pm
- Location: Argentina
Re: Discuss Joomla! 3.9.25
Looks like it still going to the wrong link in all of my website
- toivo
- Joomla! Master
- Posts: 17427
- Joined: Thu Feb 15, 2007 5:48 am
- Location: Sydney, Australia
Re: Discuss Joomla! 3.9.25
@Maradona, sorry - the link that was fixed was only in the 3.9.25 Announcement here in the forum.
The broken link 'Additional Information' in the Joomla! Update page on an actual website, for example http://example.com/administrator/index. ... omlaupdate, will now be raised as a new item in Joomla! Issue Tracker.
The broken link 'Additional Information' in the Joomla! Update page on an actual website, for example http://example.com/administrator/index. ... omlaupdate, will now be raised as a new item in Joomla! Issue Tracker.
Toivo Talikka, Global Moderator
-
- Joomla! Intern
- Posts: 60
- Joined: Thu Jan 23, 2014 6:00 pm
Re: Discuss Joomla! 3.9.25
I notice there was an issue pointed out earlier......so is it OK to do the update or should I wait for a possible 3.9.26 to replace it?
- toivo
- Joomla! Master
- Posts: 17427
- Joined: Thu Feb 15, 2007 5:48 am
- Location: Sydney, Australia
Re: Discuss Joomla! 3.9.25
The information is available from the Github link. If your website does not use folder names starting with numbers, dots or national language characters outside the range a-z A-Z, you should update to 3.9.25 but otherwise wait.
Toivo Talikka, Global Moderator
-
- Joomla! Intern
- Posts: 60
- Joined: Thu Jan 23, 2014 6:00 pm
Re: Discuss Joomla! 3.9.25
Many thanks toivo......I'll hold off and see if there's any update.
- PhilTaylor-Prazgod
- Joomla! Ace
- Posts: 1402
- Joined: Sat Aug 20, 2005 12:32 pm
- Location: Jersey, Channel Islands
- Contact:
Re: Discuss Joomla! 3.9.25
It doesn't seem that the Joomla Project is giving this any urgency at all and we are not seeing any flurry of activity for a new release urgently like previously.I notice there was an issue pointed out earlier......so is it OK to do the update or should I wait for a possible 3.9.26 to replace it?
@HLeithner has declared: "I will write a FAQ entry later today and propose a pr too."
https://github.com/joomla/joomla-cms/issues/32567
Previously they have stated that Joomla 3.9.24 was the last in the Joomla 3 series and only security releases would be considered after that. But here we are.
I would say, if you KNOW you never use folders with a starting char that is not a A-Z or a-z then you should upgrade asap to Joomla 3.9.25.
If you KNOW you DO use folders starting with other chars, including 0-9 or non-latin chars, then I would also say upgrade to Joomla 3.9.25 asap, and then modify the line in question to add your additional characters to the regex (or remove the "return false" in the regex check.
Remember that this is only one security fix amongst the nine fixed in Joomla 3.9.25 (although two others are contested).
There is a new Joomla 3.9.26 milestone created in GitHub, so there "will probably be" a Joomla 3.9.26, if the project so decides.
https://github.com/joomla/joomla-cms/milestone/67
Phil Taylor
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/
-
- Joomla! Intern
- Posts: 60
- Joined: Thu Jan 23, 2014 6:00 pm
Re: Discuss Joomla! 3.9.25
Thanks Phil!PhilTaylor-Prazgod wrote: ↑Wed Mar 03, 2021 11:06 amIt doesn't seem that the Joomla Project is giving this any urgency at all and we are not seeing any flurry of activity for a new release urgently like previously.I notice there was an issue pointed out earlier......so is it OK to do the update or should I wait for a possible 3.9.26 to replace it?
@HLeithner has declared: "I will write a FAQ entry later today and propose a pr too."
https://github.com/joomla/joomla-cms/issues/32567
Previously they have stated that Joomla 3.9.24 was the last in the Joomla 3 series and only security releases would be considered after that. But here we are.
I would say, if you KNOW you never use folders with a starting char that is not a A-Z or a-z then you should upgrade asap to Joomla 3.9.25.
If you KNOW you DO use folders starting with other chars, including 0-9 or non-latin chars, then I would also say upgrade to Joomla 3.9.25 asap, and then modify the line in question to add your additional characters to the regex (or remove the "return false" in the regex check.
Remember that this is only one security fix amongst the nine fixed in Joomla 3.9.25 (although two others are contested).
There is a new Joomla 3.9.26 milestone created in GitHub, so there "will probably be" a Joomla 3.9.26, if the project so decides.
https://github.com/joomla/joomla-cms/milestone/67
I know for a fact that some sites will have image folders starting with numbers so I'm just going to hold off until we get some sort of update to this.
- PhilTaylor-Prazgod
- Joomla! Ace
- Posts: 1402
- Joined: Sat Aug 20, 2005 12:32 pm
- Location: Jersey, Channel Islands
- Contact:
Re: Discuss Joomla! 3.9.25
And to be clear. This is NOT just about image folders.
This is about any folder path that is validated by the joomla file path rule class.
This could effect 3rd party extensions if they implement that rule too.
This is about any folder path that is validated by the joomla file path rule class.
This could effect 3rd party extensions if they implement that rule too.
Phil Taylor
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/
-
- Joomla! Intern
- Posts: 70
- Joined: Sat Nov 26, 2005 9:10 pm
Re: Discuss Joomla! 3.9.25
There is a saying in the United States "it takes a big man to admit when he's wrong" (and yes, I do wear a mask - and yes, I did consider moving out of the country - and yes, I am hesitant to even admit I live here after the last four years)
Based on my read of this situation, we have egos getting in the way of customer service. This shouldn't be about who is right and who is wrong but about providing the community with a quality product. I get that as a community we rely on great people to make Joomla a reality but I will leave with some food for thought.
If you were this same role and you introduced this bug to your paying customers, would you fix it immediately?
Based on my read of this situation, we have egos getting in the way of customer service. This shouldn't be about who is right and who is wrong but about providing the community with a quality product. I get that as a community we rely on great people to make Joomla a reality but I will leave with some food for thought.
If you were this same role and you introduced this bug to your paying customers, would you fix it immediately?
-
- Joomla! Explorer
- Posts: 359
- Joined: Thu Jun 14, 2007 2:48 pm
- Location: Coppell, Texas
- Contact:
Re: Discuss Joomla! 3.9.25
Do we know when they plan to release 3.9.26 to fix the bug introduced by 3.9.25? I prefer not to upgrade to a release that can introduce problems for a currently functioning website, Thanks for any info you can provide!
-
- Joomla! Intern
- Posts: 60
- Joined: Thu Jan 23, 2014 6:00 pm
Re: Discuss Joomla! 3.9.25
I find it odd that this announcement went out on Twitter yesterday:
A bug has been introduced in 3.9.25 and the Release Team is working on a fix. We are sorry for the inconvenience. Stay tuned!
But I can't see any official announcement here.
A bug has been introduced in 3.9.25 and the Release Team is working on a fix. We are sorry for the inconvenience. Stay tuned!
But I can't see any official announcement here.
- toivo
- Joomla! Master
- Posts: 17427
- Joined: Thu Feb 15, 2007 5:48 am
- Location: Sydney, Australia
Re: Discuss Joomla! 3.9.25
The release FAQ mentions the issue: Version 3.9.25 FAQ
Toivo Talikka, Global Moderator
-
- Joomla! Apprentice
- Posts: 44
- Joined: Sat Feb 03, 2018 2:03 pm
Re: Discuss Joomla! 3.9.25
3 sites updated without any problem. Thanks Joomla! team!
- ribo
- Joomla! Virtuoso
- Posts: 3507
- Joined: Sun Jan 03, 2010 8:47 pm
- Contact:
Re: Discuss Joomla! 3.9.25
Updating many joomla sites without any issue. Thank you joomla team
chat room spontes : http://www.spontes.com
-
- Joomla! Intern
- Posts: 80
- Joined: Mon Sep 03, 2012 2:25 pm
Re: Discuss Joomla! 3.9.25
About ten wesites updated to Joomla 3.9.25 from 3.9.24 with concern and apprehension in view of the above messages.
All went well. Configuration: Joomla, JCE;, Templates Yootheme warp 7, Hikashop, Widgetkit etc ...
Thanks to the Joomla team for this work!
All went well. Configuration: Joomla, JCE;, Templates Yootheme warp 7, Hikashop, Widgetkit etc ...
Thanks to the Joomla team for this work!
- Jaydot
- Joomla! Guru
- Posts: 651
- Joined: Sun Jun 04, 2017 12:11 pm
- Location: The Netherlands
- Contact:
Re: Discuss Joomla! 3.9.25
20+ sites updated flawlessly.
(I didn't expect the bug to affect my sites - and as far as I can tell, it didn't).
Thanks, Joomla team.
(I didn't expect the bug to affect my sites - and as far as I can tell, it didn't).
Thanks, Joomla team.
The fact that an opinion is widely held is no evidence whatsoever that it is not utterly absurd.
Personal website: https://jaydot.nl
Personal website: https://jaydot.nl
-
- Joomla! Intern
- Posts: 60
- Joined: Thu Jan 23, 2014 6:00 pm
Re: Discuss Joomla! 3.9.25
I'm still holding off.....I'm not taking the risk.
- ribo
- Joomla! Virtuoso
- Posts: 3507
- Joined: Sun Jan 03, 2010 8:47 pm
- Contact:
Re: Discuss Joomla! 3.9.25
There is not any risk if you always back up before.
chat room spontes : http://www.spontes.com
-
- Joomla! Intern
- Posts: 60
- Joined: Thu Jan 23, 2014 6:00 pm
Re: Discuss Joomla! 3.9.25
I have many sites......it would take me all day to restore the lot.
Plus it would be disruption to business sites......that can't happen.
- leolam
- Joomla! Master
- Posts: 20652
- Joined: Mon Aug 29, 2005 10:17 am
- Location: Netherlands/ Germany/ S'pore/Bogor/ North America
- Contact:
Re: Discuss Joomla! 3.9.25
As posted on Github on the issue:
LeoWhy are we so stupid and ignorant @HLeithner not to simply do a quick release where thousands of website are broken because of this? i personally can add or remove line in a piece of code but many users cannot or don't care. A reference to a FAQ does not work since we all know that nobody reads the notes or FAQ...." If I have a problem how should I know that I have to look at FAQ's?" These are not posted on the Joomla forums so most users have no way to find out why the release broke their site
Get a release with a fix out ...you are in charge so do something quick for this community please? Typing many reactions here and elsewhere takes you more time then simply changing a few lines of code and releasing the patch! Get over your pride and spend 30 minutes to get this issue solved!!!
Joomla's #1 Professional Services Provider:
#Joomla Professional Support: https://gws-desk.com -
#Joomla Specialized Hosting Solutions: https://gws-host.com -
#Joomla Professional Support: https://gws-desk.com -
#Joomla Specialized Hosting Solutions: https://gws-host.com -