Changelog for
joomla-3.10.11-1.12.noarch.rpm :
* Tue Oct 25 2022 Adrian Schröter
- update to 3.10.11
* Fixes for migration to version 4
* Tue Oct 25 2022 Adrian Schröter - drop reference to google font server in default theme to be in sync with DSGVO regulation
* Fri Mar 18 2022 Adrian Schröter - Update to 3.10.6
* Should be used to prepare upgrade to joomla4 package
* Mon Feb 07 2022 Lars Vogdt - Update to 3.10.5
* Privacy requests and confirmation can now be made by logged-in users only (#35470)
* Improve the message for the backups to specifically include the \'filesystem\' and the \'database\' (#36494)
* Fix an regression with the Progressive caching to cache modules per custom menu assignment (#36324)
* Update simplepie to 1.3.3 (#36358)
* PHP 8.1 compatibility patches (#36083, #35485) Please note if you show \'all errors\' there could be deprication notices on some pages.
* Update cacert.pem as of: Tue Oct 26 03:12:05 2021 GMT (#35955)
* Fix wrong input filter type for extension names of site and admin languages in the extensions installer (#35980)
* Fix tinymce issues when resorting happens (#34808)
* Fix an calendar error with IE11 (#35819)
* Update the cacert file (#35785)
* Improve the loading of tags on the contacts component (#35764)
* Mon Sep 20 2021 Lars Vogdt - Update to 3.10.2
* Fix misleading \"Update Required\" in the pre-update checker #35510
* Fix javascript error for pre-update checker #35481
* Change text when com_joomlaupdate update available #35373
* fix language string case message for old sts settings
* Fri Aug 20 2021 Adrian Schröter - Update to 3.10.0- Pre-Requirement for a joomla 4.x update!
* Mon Jul 19 2021 Lars Vogdt - Update to 3.9.28 Security Issues Fixed
* Low Severity - Low Impact - XSS in JForm Rules field
* Low Severity - Low Impact - DoS through usergroup table manipulation
* Low Severity - Moderate Impact - Lack of enforced session termination
* Low Severity - High Impact - Privilege escalation through com_installer
* Low Severity - Moderate Impact - XSS in com_media imagelist Bug fixes and Improvements
* Update CA certificates #34693
* Smart Search: Fix inserting tokens to DB #34497
* Fix search suggestions for mixed-case searches #33942
* Wed Jun 02 2021 Lars Vogdt - Update to 3.9.27 Security Issues Fixed
* Low Severity - Low Impact - Adding HTML to the executable block list of MediaHelper::canUpload
* Low Severity - Low Impact - CSRF in AJAX reordering endpoint
* Low Severity - Low Impact - CSRF in data download endpoints Bug fixes and Improvements
* Disable FLoC by default #33212
* Postgres compatibility fixes for smart search #31809
* Allow objects stored in tables as json #33633
* Improve indexing performance of Smart Search #33720
* Addional PHP 8 improvment #33113
* Sun Apr 18 2021 Adrian Schröter - Update to 3.9.26 Security Issues Fixed
* Low Severity - Low Impact - Escape xss in logo parameter error pages
* Low Severity - Low Impact - Inadequate filters on module layout settings Bug fixes and Improvements
* Fix caching issues after rebuilding update sites #33040
* Allow to configure load balancer/reverse proxy setting #32866
* Fix loosing extra query parameter for update sites #32862
* MySQL and MariaDB compatibility fixes #32605
* Fix frontend create article permission #32470
* Update CodeMirror to 5.60.0 #32926
* Addional PHP 8 improvment #32767
* Wed Mar 03 2021 Lars Vogdt - Update to 3.9.25 Security Issues Fixed (CVE-2021-23126, CVE-2021-23127, CVE-2021-23128, CVE-2021-23129, CVE-2021-23130, CVE-2021-23132, CVE-2021-26027, CVE-2021-26029) + Insecure randomness within 2FA secret generation + Potential Insecure FOFEncryptRandval + XSS within alert messages showed to users + XSS within the feed parser library + Input validation within the template manager + com_media allowed paths that are not intended for image uploads + ACL violation within com_content frontend editing + Path Traversal within joomla/archive zip class + Inadequate filtering of form contents could allow to overwrite the author field Bug fixes and Improvements + Fix Save as Copy tag #32454 + Fix published attribute for Tag field #32332 + Fix batch menu items #32380 + Stream transport should enable verify_peer_name when possible #16501 + Optimize the code for rename incorrectly cased files on update #32176 + Addional PHP 8 improvments #31977 #32374
* Wed Feb 24 2021 Adrian Schröter - update to 3.9.24 Security Issues Fixed (CVE-2021-23123, CVE-2021-23124 and CVE-2021-23125)
* Low Severity - Low Impact - com_modules exposes module names (affecting Joomla! 3.0.0 through 3.9.23) More information »
* Low Severity - Moderate Impact - XSS in mod_breadcrumbs aria-label attribute (affecting Joomla! 3.9.0 through 3.9.23) More information »
* Low Severity - Moderate Impact - XSS in com_tags image parameters (affecting Joomla! 3.1.0 through 3.9.23) More information » Bug fixes and Improvements
* Continuing to improve PHP 8 support #31628 #31537 #31536 #30921
* Solved performance issue with zip archives containing zip files #31514
* Removes deprecate feature-policy and adds the new Permissions Policy #30819
* Update joomla/image dependency #31663
* Fixed regression SMTP Settings Test #31724
* Fixed regression to save empty passwords in global configuration #31672