Security Announcements
This feed provides announcements of resolved security issues in Joomla! software releases.
For more information about the Joomla! Security Strike Team (JSST) and its processes, please review our Security article.
To report potential security issues, please follow the guidelines in the above referenced article. Please note that we are only able to provide support for the Joomla! CMS, Joomla! Framework, and *.joomla.org network of websites.
You can subscribe to notifications from this feed through a RSS reader.
- Project: Joomla!
- SubProject: CMS
- Severity: Low
- Versions: 3.7.0 through 3.7.5
- Exploit type: Information Disclosure
- Reported Date: 2017-August-4
- Fixed Date: 2017-September-19
- CVE Number: CVE-2017-14595
Description
A logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.
Affected Installs
Joomla! CMS versions 3.7.0 through 3.7.5
Solution
Upgrade to version 3.8.0
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Severity: Medium
- Versions: 1.5.0 through 3.7.5
- Exploit type: Information Disclosure
- Reported Date: 2017-July-27
- Fixed Date: 2017-September-19
- CVE Number: CVE-2017-14596
Description
Inadequate escaping in the LDAP authentication plugin can result into a disclosure of username and password.
Affected Installs
Joomla! CMS versions 1.5.0 through 3.7.5
Solution
Upgrade to version 3.8.0
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS Installer
- Severity: High
- Versions: 1.0.0 through 3.7.3
- Exploit type: Lack of Ownership Verification
- Reported Date: 2017-Apr-06
- Fixed Date: 2017-July-25
- CVE Number: CVE-2017-11364
Description
The CMS installer application lacked a process to verify the users ownership of a webspace, potentially allowing users to gain control.
Please note: Already installed sites are not affected, as this issue is limited to the installer application!
Affected Installs
Joomla! CMS versions 1.0.0 through 3.7.3
Solution
Upgrade to version 3.7.4
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Severity: Low
- Versions: 1.5.0 through 3.7.3
- Exploit type: XSS
- Reported Date: 2017-April-26
- Fixed Date: 2017-July-25
- CVE Number: CVE-2017-11612
Description
Inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components.
Affected Installs
Joomla! CMS versions 1.5.0 through 3.7.3
Solution
Upgrade to version 3.7.4
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Severity: High
- Versions: 1.7.3 - 3.7.2
- Exploit type: Information Disclosure
- Reported Date: 2016-Feb-05
- Fixed Date: 2017-July-04
- CVE Number: CVE-2017-9933
Description
Improper cache invalidation leads to disclosure of form contents.
Affected Installs
Joomla! CMS versions 1.7.3-3.7.2
Solution
Upgrade to version 3.7.3
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Severity: High
- Versions: 1.7.3 - 3.7.2
- Exploit type: XSS
- Reported Date: 2017-June-04
- Fixed Date: 2017-July-04
- CVE Number: CVE-2017-9934
Description
Missing CSRF token checks and improper input validation lead to an XSS vulnerability.
Affected Installs
Joomla! CMS versions 1.7.3-3.7.2
Solution
Upgrade to version 3.7.3
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Severity: Low
- Versions: 1.5.0 through 3.7.2
- Exploit type: XSS
- Reported Date: 2017-June-22
- Fixed Date: 2017-July-04
- CVE Number: CVE-2017-7985
Description
Inadequate filtering of multibyte characters leads to XSS vulnerabilities in various components.
Affected Installs
Joomla! CMS versions 1.5.0 through 3.6.5
Solution
Upgrade to version 3.7.3
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Severity: High
- Versions: 3.7.0
- Exploit type: SQL Injection
- Reported Date: 2017-May-11
- Fixed Date: 2017-May-17
- CVE Number: CVE-2017-8917
Description
Inadequate filtering of request data leads to a SQL Injection vulnerability.
Affected Installs
Joomla! CMS versions 3.7.0
Solution
Upgrade to version 3.7.1
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Severity: Low
- Versions: 3.4.0 through 3.6.5
- Exploit type: Information Disclosure
- Reported Date: 2016-Feb-06
- Fixed Date: 2017-April-25
- CVE Number: CVE-2017-8057
Description
Multiple files caused full path disclosures on systems with enabled error reporting.
Affected Installs
Joomla! CMS versions 3.4.0 through 3.6.5
Solution
Upgrade to version 3.7.0
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Severity: Low
- Versions: 3.2.0 through 3.6.5
- Exploit type: ACL Violation
- Reported Date: 2017-March-01
- Fixed Date: 2017-April-25
- CVE Number: CVE-2017-7989
Description
Inadequate mime type checks allowed low-privilege users to upload swf files even if they were explicitly forbidden.
Affected Installs
Joomla! CMS versions 3.2.0 through 3.6.5
Solution
Upgrade to version 3.7.0
Contact
The JSST at the Joomla! Security Centre.