Keyword

JED has Unpublished K2 due to Security Risk !

  • Tracey
  • Tracey's Avatar Topic Author
  • Offline
  • Senior Member
More
10 years 3 months ago - 10 years 3 months ago #129230 by Tracey
Searching the JED and to my surprise I came across this:
extensions.joomla.org/extensions/authoring-a-content/content-construction/8061#rev-118224

Message also states "You should also immediately get in contact with the developer of this extension and inquire about fixes to this security risk."

How serious is this?

Is there a fix?

Thanks

Joomla! v3.5.1
Gantry5 - Hydrogen Template
k2 v2.7.0

Please Log in or Create an account to join the conversation.

More
10 years 3 months ago #129231 by Daniel
Hi Tracey,
yeah saw this one on the VEL rss feed earlier this morning.

But it doesn't say what the deal is - just that K2 is vulnerable.
  • Does it mean that specifically v2.6.8 is vulnerable? (and that all previous versions are not?)
  • Or could this vulnerability apply to any version?

I'd imagine it'd just mean v2.6.8, but there isn't much info that I could find on what the vulnerability even is. Am definitely not going to update to 2.6.8 until we find out either way (and how serious it is).

Cheers,

Please Log in or Create an account to join the conversation.

More
10 years 3 months ago #129232 by Tudor Drugan
Replied by Tudor Drugan on topic Re: JED has Unpublished K2 due to Security Risk !
K2 Content Extension, 2.6.8,
Published on Tuesday, 10 June 2014 22:03

K2 Content Extension, 2.6.8, XSS (Cross Site Scripting)

link

Please Log in or Create an account to join the conversation.

  • Tracey
  • Tracey's Avatar Topic Author
  • Offline
  • Senior Member
More
10 years 3 months ago #129233 by Tracey
Hi Daniel,

Yeah unfortunately like you said theres not much if any info on this and it's got me a bit
freaked out.

Hopefully the k2 team will get right on this and have a fix. I'm running v2.6.8 and also as you said it's probably just for that version since that was the version that was offered for download.

Lets keep our fingers crossed for a fix!

Regards,

Joomla! v3.5.1
Gantry5 - Hydrogen Template
k2 v2.7.0

Please Log in or Create an account to join the conversation.

More
10 years 3 months ago #129234 by Lefteris
I would like to inform anyone worrying about this that everything is fine. Your sites are NOT under a security risk. No exploit can be applied to what they have found, so actually this is not even an XSS vulnerability. Of course K2 will be updated and will be back to the JED.

JoomlaWorks Support Team
---
Please search the forum before posting a new topic :)

Please Log in or Create an account to join the conversation.

More
10 years 3 months ago #129235 by JoomlaWorks
Replied by JoomlaWorks on topic Re: JED has Unpublished K2 due to Security Risk !

Fotis / JoomlaWorks Support Team
---
Please search the forum before posting a new topic :)

Please Log in or Create an account to join the conversation.

  • Tracey
  • Tracey's Avatar Topic Author
  • Offline
  • Senior Member
More
10 years 3 months ago #129236 by Tracey
Good to know its nothing serious.

Thanks for the link explaining what the problem is.

Regards,
Tracey

Joomla! v3.5.1
Gantry5 - Hydrogen Template
k2 v2.7.0

Please Log in or Create an account to join the conversation.

More
10 years 3 months ago #129237 by Daniel
Thanks guys for the clarification!
Great to hear it's nothing serious

Please Log in or Create an account to join the conversation.

More
10 years 3 months ago #129238 by JoomlaWorks
Replied by JoomlaWorks on topic Re: JED has Unpublished K2 due to Security Risk !
Thankfully, the JED team has republished K2.

Still waiting for the VEL team to either reply that we're wrong (and why) or remove their false report.

Fotis / JoomlaWorks Support Team
---
Please search the forum before posting a new topic :)

Please Log in or Create an account to join the conversation.


Powered by Kunena Forum