CVE-2021-23128

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/03/2021
Last modified:
05/03/2021

Description

An issue was discovered in Joomla! 3.2.0 through 3.9.24. The core shipped but unused randval implementation within FOF (FOFEncryptRandval) used an potential insecure implemetation. That has now been replaced with a call to 'random_bytes()' and its backport that is shipped within random_compat.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:* 3.2.0 (including) 3.9.25 (excluding)