- Posts: 47
COMMUNITY FORUM
JED has Unpublished K2 due to Security Risk !
- Tracey
-
Topic Author
- Offline
- Senior Member
Less
More
10 years 11 months ago - 10 years 11 months ago #129230
by Tracey
Joomla! v3.5.1
Gantry5 - Hydrogen Template
k2 v2.7.0
JED has Unpublished K2 due to Security Risk ! was created by Tracey
Searching the JED and to my surprise I came across this:
extensions.joomla.org/extensions/authoring-a-content/content-construction/8061#rev-118224
Message also states "You should also immediately get in contact with the developer of this extension and inquire about fixes to this security risk."
How serious is this?
Is there a fix?
Thanks
extensions.joomla.org/extensions/authoring-a-content/content-construction/8061#rev-118224
Message also states "You should also immediately get in contact with the developer of this extension and inquire about fixes to this security risk."
How serious is this?
Is there a fix?
Thanks
Joomla! v3.5.1
Gantry5 - Hydrogen Template
k2 v2.7.0
Please Log in or Create an account to join the conversation.
- Daniel
-
- Offline
- New Member
Less
More
- Posts: 2
10 years 11 months ago #129231
by Daniel
Replied by Daniel on topic Re: JED has Unpublished K2 due to Security Risk !
Hi Tracey,
yeah saw this one on the VEL rss feed earlier this morning.
But it doesn't say what the deal is - just that K2 is vulnerable.
I'd imagine it'd just mean v2.6.8, but there isn't much info that I could find on what the vulnerability even is. Am definitely not going to update to 2.6.8 until we find out either way (and how serious it is).
Cheers,
yeah saw this one on the VEL rss feed earlier this morning.
But it doesn't say what the deal is - just that K2 is vulnerable.
- Does it mean that specifically v2.6.8 is vulnerable? (and that all previous versions are not?)
- Or could this vulnerability apply to any version?
I'd imagine it'd just mean v2.6.8, but there isn't much info that I could find on what the vulnerability even is. Am definitely not going to update to 2.6.8 until we find out either way (and how serious it is).
Cheers,
Please Log in or Create an account to join the conversation.
- Tudor Drugan
-
- Offline
- New Member
Less
More
- Posts: 10
10 years 11 months ago #129232
by Tudor Drugan
Replied by Tudor Drugan on topic Re: JED has Unpublished K2 due to Security Risk !
K2 Content Extension, 2.6.8,
Published on Tuesday, 10 June 2014 22:03
K2 Content Extension, 2.6.8, XSS (Cross Site Scripting)
link
Published on Tuesday, 10 June 2014 22:03
K2 Content Extension, 2.6.8, XSS (Cross Site Scripting)
link
Please Log in or Create an account to join the conversation.
- Tracey
-
Topic Author
- Offline
- Senior Member
Less
More
- Posts: 47
10 years 11 months ago #129233
by Tracey
Joomla! v3.5.1
Gantry5 - Hydrogen Template
k2 v2.7.0
Replied by Tracey on topic Re: JED has Unpublished K2 due to Security Risk !
Hi Daniel,
Yeah unfortunately like you said theres not much if any info on this and it's got me a bit
freaked out.
Hopefully the k2 team will get right on this and have a fix. I'm running v2.6.8 and also as you said it's probably just for that version since that was the version that was offered for download.
Lets keep our fingers crossed for a fix!
Regards,
Yeah unfortunately like you said theres not much if any info on this and it's got me a bit
freaked out.
Hopefully the k2 team will get right on this and have a fix. I'm running v2.6.8 and also as you said it's probably just for that version since that was the version that was offered for download.
Lets keep our fingers crossed for a fix!
Regards,
Joomla! v3.5.1
Gantry5 - Hydrogen Template
k2 v2.7.0
Please Log in or Create an account to join the conversation.
- Lefteris
-
- Offline
- Platinum Member
Less
More
- Posts: 8743
10 years 11 months ago #129234
by Lefteris
Replied by Lefteris on topic Re: JED has Unpublished K2 due to Security Risk !
I would like to inform anyone worrying about this that everything is fine. Your sites are NOT under a security risk. No exploit can be applied to what they have found, so actually this is not even an XSS vulnerability. Of course K2 will be updated and will be back to the JED.
Please Log in or Create an account to join the conversation.
- JoomlaWorks
-
- Offline
- Admin
Less
More
- Posts: 6227
10 years 11 months ago #129235
by JoomlaWorks
Replied by JoomlaWorks on topic Re: JED has Unpublished K2 due to Security Risk !
Please Log in or Create an account to join the conversation.
- Tracey
-
Topic Author
- Offline
- Senior Member
Less
More
- Posts: 47
10 years 11 months ago #129236
by Tracey
Joomla! v3.5.1
Gantry5 - Hydrogen Template
k2 v2.7.0
Replied by Tracey on topic Re: JED has Unpublished K2 due to Security Risk !
Good to know its nothing serious.
Thanks for the link explaining what the problem is.
Regards,
Tracey
Thanks for the link explaining what the problem is.
Regards,
Tracey
Joomla! v3.5.1
Gantry5 - Hydrogen Template
k2 v2.7.0
Please Log in or Create an account to join the conversation.
- Daniel
-
- Offline
- New Member
Less
More
- Posts: 2
10 years 11 months ago #129237
by Daniel
Replied by Daniel on topic Re: JED has Unpublished K2 due to Security Risk !
Thanks guys for the clarification!
Great to hear it's nothing serious
Great to hear it's nothing serious
Please Log in or Create an account to join the conversation.
- JoomlaWorks
-
- Offline
- Admin
Less
More
- Posts: 6227
10 years 11 months ago #129238
by JoomlaWorks
Replied by JoomlaWorks on topic Re: JED has Unpublished K2 due to Security Risk !
Thankfully, the JED team has republished K2.
Still waiting for the VEL team to either reply that we're wrong (and why) or remove their false report.
Still waiting for the VEL team to either reply that we're wrong (and why) or remove their false report.
Please Log in or Create an account to join the conversation.