J3 Issue ?
avatar LoRexxar
LoRexxar
20 Jun 2019

Is your feature request related to a problem? Please describe.

typo3 phar-steam-wrapper 2.1.1 and 2.1.2 update and fix some bugs. and some bugs affect my use, I hope to update this plugin。

Describe the solution you'd like

update typo3 phar-steam-wrapper to 2.1.2

Additional context

https://github.com/TYPO3/phar-stream-wrapper/releases

avatar LoRexxar LoRexxar - open - 20 Jun 2019
avatar joomla-cms-bot joomla-cms-bot - change - 20 Jun 2019
Labels Added: ?
avatar joomla-cms-bot joomla-cms-bot - labeled - 20 Jun 2019
avatar LoRexxar
LoRexxar - comment - 20 Jun 2019

there are a secrutiy issue update in 2.1.1

https://typo3.org/security/advisory/typo3-psa-2019-008/

i think it will make my joomla cms be unsafe , Although I don't know how the problem will occur, I want to protect my server.

avatar HLeithner
HLeithner - comment - 20 Jun 2019

The security problem you mention has been fixed in Joomla! 3.9.6 as
[20190502] - Core - By-passing protection of Phar Stream Wrapper Interceptor
https://developer.joomla.org/security-centre.html

I will do a composer update and create a PR for it, you can test this later today.

avatar franz-wohlkoenig franz-wohlkoenig - change - 20 Jun 2019
Labels Added: J3 Issue
avatar franz-wohlkoenig franz-wohlkoenig - labeled - 20 Jun 2019
avatar franz-wohlkoenig
franz-wohlkoenig - comment - 20 Jun 2019

Closed as having Pull Request #25279

avatar franz-wohlkoenig franz-wohlkoenig - change - 20 Jun 2019
Status New Closed
Closed_Date 0000-00-00 00:00:00 2019-06-20 09:18:32
Closed_By franz-wohlkoenig
avatar franz-wohlkoenig franz-wohlkoenig - close - 20 Jun 2019

Add a Comment

Login with GitHub to post a comment