CINXE.COM
Joomla! Security
<!DOCTYPE html> <html lang="en-gb" dir="ltr"> <head><script type="text/javascript" src="https://web-static.archive.org/_static/js/bundle-playback.js?v=7YQSqjSh" charset="utf-8"></script> <script type="text/javascript" src="https://web-static.archive.org/_static/js/wombat.js?v=txqj7nKC" charset="utf-8"></script> <script>window.RufflePlayer=window.RufflePlayer||{};window.RufflePlayer.config={"autoplay":"on","unmuteOverlay":"hidden"};</script> <script type="text/javascript" src="https://web-static.archive.org/_static/js/ruffle/ruffle.js"></script> <script type="text/javascript"> __wm.init("https://web.archive.org/web"); __wm.wombat("https://developer.joomla.org/security.html","20170628154843","https://web.archive.org/","web","https://web-static.archive.org/_static/", "1498664923"); </script> <link rel="stylesheet" type="text/css" href="https://web-static.archive.org/_static/css/banner-styles.css?v=p7PEIJWi" /> <link rel="stylesheet" type="text/css" href="https://web-static.archive.org/_static/css/iconochive.css?v=3PDvdIFv" /> <!-- End Wayback Rewrite JS Include --> <meta charset="utf-8"/> <base href="https://web.archive.org/web/20170628154843/https://developer.joomla.org/security.html"/> <meta name="author" content="Joomla! Security Strike Team"/> <meta name="viewport" content="width=device-width, initial-scale=1.0"/> <meta name="apple-mobile-web-app-capable" content="yes"/> <meta name="apple-mobile-web-app-status-bar-style" content="blue"/> <meta name="twitter:card" content="summary_large_image"/> <meta name="twitter:site" content="@joomla"/> <meta name="twitter:description" content="The Platform Millions of Websites Are Built On"/> <meta name="twitter:image" content="https://web.archive.org/web/20170628154843im_/https://cdn.joomla.org/images/sharing/joomla-twitter-card.png"/> <meta name="twitter:title" content="Joomla! Developer Network"/> <meta name="referrer" content="unsafe-url"/> <meta property="og:site_name" content="Joomla! Developer Network™"/> <meta property="og:image" content="https://web.archive.org/web/20170628154843im_/https://cdn.joomla.org/images/sharing/joomla-org-og.jpg"/> <meta name="generator" content="Joomla! - Open Source Content Management"/> <title>Joomla! Security</title> <link href="/web/20170628154843im_/https://developer.joomla.org/templates/joomla/images/apple-touch-icon-180x180.png" rel="apple-touch-icon" sizes="180x180"/> <link href="/web/20170628154843im_/https://developer.joomla.org/templates/joomla/images/apple-touch-icon-152x152.png" rel="apple-touch-icon" sizes="152x152"/> <link href="/web/20170628154843im_/https://developer.joomla.org/templates/joomla/images/apple-touch-icon-144x144.png" rel="apple-touch-icon" sizes="144x144"/> <link href="/web/20170628154843im_/https://developer.joomla.org/templates/joomla/images/apple-touch-icon-120x120.png" rel="apple-touch-icon" sizes="120x120"/> <link href="/web/20170628154843im_/https://developer.joomla.org/templates/joomla/images/apple-touch-icon-114x114.png" rel="apple-touch-icon" sizes="114x114"/> <link href="/web/20170628154843im_/https://developer.joomla.org/templates/joomla/images/apple-touch-icon-76x76.png" rel="apple-touch-icon" sizes="76x76"/> <link href="/web/20170628154843im_/https://developer.joomla.org/templates/joomla/images/apple-touch-icon-72x72.png" rel="apple-touch-icon" sizes="72x72"/> <link href="/web/20170628154843im_/https://developer.joomla.org/templates/joomla/images/apple-touch-icon-57x57.png" rel="apple-touch-icon" sizes="57x57"/> <link href="/web/20170628154843im_/https://developer.joomla.org/templates/joomla/images/apple-touch-icon.png" rel="apple-touch-icon"/> <link href="/web/20170628154843im_/https://developer.joomla.org/templates/joomla/favicon.ico" rel="shortcut icon" type="image/vnd.microsoft.icon"/> <link href="/web/20170628154843cs_/https://developer.joomla.org/templates/joomla/css/template.min.css?2.2.1-dev" rel="stylesheet"/> <link href="/web/20170628154843cs_/https://developer.joomla.org/templates/joomla/css/custom.css?4e9519d2a6b1b4666f7f89df79ba18fe" rel="stylesheet"/> <link href="https://web.archive.org/web/20170628154843cs_/https://fonts.googleapis.com/css?family=Open+Sans" rel="stylesheet"/> <link href="/web/20170628154843cs_/https://developer.joomla.org/media/jui/css/chosen.css?4e9519d2a6b1b4666f7f89df79ba18fe" rel="stylesheet"/> <link href="/web/20170628154843cs_/https://developer.joomla.org/media/com_finder/css/finder.css?4e9519d2a6b1b4666f7f89df79ba18fe" rel="stylesheet"/> <style> h1, h2, h3, h4, h5, h6 { font-family: 'Open Sans', sans-serif; } </style> <script src="/web/20170628154843js_/https://developer.joomla.org/media/jui/js/jquery.min.js?4e9519d2a6b1b4666f7f89df79ba18fe"></script> <script src="/web/20170628154843js_/https://developer.joomla.org/media/jui/js/jquery-noconflict.js?4e9519d2a6b1b4666f7f89df79ba18fe"></script> <script src="/web/20170628154843js_/https://developer.joomla.org/media/jui/js/jquery-migrate.min.js?4e9519d2a6b1b4666f7f89df79ba18fe"></script> <script src="/web/20170628154843js_/https://developer.joomla.org/media/system/js/caption.js?4e9519d2a6b1b4666f7f89df79ba18fe"></script> <script src="/web/20170628154843js_/https://developer.joomla.org/media/jui/js/bootstrap.min.js?4e9519d2a6b1b4666f7f89df79ba18fe"></script> <script src="/web/20170628154843js_/https://developer.joomla.org/templates/joomla/js/template.js?4e9519d2a6b1b4666f7f89df79ba18fe"></script> <script src="/web/20170628154843js_/https://developer.joomla.org/templates/joomla/js/blockadblock.js?4e9519d2a6b1b4666f7f89df79ba18fe"></script> <script src="/web/20170628154843js_/https://developer.joomla.org/templates/joomla/js/js.cookie.js?4e9519d2a6b1b4666f7f89df79ba18fe"></script> <!--[if lt IE 9]><script src="/media/jui/js/html5.js?4e9519d2a6b1b4666f7f89df79ba18fe"></script><![endif]--> <script src="/web/20170628154843js_/https://developer.joomla.org/media/jui/js/chosen.jquery.min.js?4e9519d2a6b1b4666f7f89df79ba18fe"></script> <script src="/web/20170628154843js_/https://developer.joomla.org/media/jui/js/jquery.autocomplete.min.js?4e9519d2a6b1b4666f7f89df79ba18fe"></script> <script> jQuery(window).on('load', function() { new JCaption('img.caption'); }); jQuery(function($){ $(".hasTooltip").tooltip({"html": true,"container": "body"}); }); jQuery(function ($) { initChosen(); $("body").on("subform-row-add", initChosen); function initChosen(event, container) { container = container || document; $(container).find(".advancedSelect").chosen({"disable_search_threshold":10,"search_contains":true,"allow_single_deselect":true,"placeholder_text_multiple":"Type or select some options","placeholder_text_single":"Select an option","no_results_text":"No results match"}); } }); jQuery(document).ready(function() { var value, searchword = jQuery('#mod-finder-searchword84'); // Get the current value. value = searchword.val(); // If the current value equals the default value, clear it. searchword.on('focus', function () { var el = jQuery(this); if (el.val() === 'Search ...') { el.val(''); } }); // If the current value is empty, set the previous value. searchword.on('blur', function () { var el = jQuery(this); if (!el.val()) { el.val(value); } }); jQuery('#mod-finder-searchform84').on('submit', function (e) { e.stopPropagation(); var advanced = jQuery('#mod-finder-advanced84'); // Disable select boxes with no value selected. if (advanced.length) { advanced.find('select').each(function (index, el) { var el = jQuery(el); if (!el.val()) { el.attr('disabled', 'disabled'); } }); } }); var suggest = jQuery('#mod-finder-searchword84').autocomplete({ serviceUrl: '/component/finder/?task=suggestions.suggest&format=json&tmpl=component', paramName: 'q', minChars: 1, maxHeight: 400, width: 300, zIndex: 9999, deferRequestBy: 500 });}); </script> <script> var _prum = [['id', '59300ad15992c776ad970068'], ['mark', 'firstbyte', (new Date()).getTime()]]; (function() { var s = document.getElementsByTagName('script')[0] , p = document.createElement('script'); p.async = 'async'; p.src = '//web.archive.org/web/20170628154843/https://rum-static.pingdom.net/prum.min.js'; s.parentNode.insertBefore(p, s); })(); </script> </head> <body class="site com_content view-article layout-default task-display itemid-516"> <!-- Google Tag Manager --> <noscript><iframe src="//web.archive.org/web/20170628154843if_/https://www.googletagmanager.com/ns.html?id=GTM-WJ36D4" height="0" width="0" style="display:none;visibility:hidden"></iframe></noscript> <script>(function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='//web.archive.org/web/20170628154843/https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-WJ36D4');</script> <!-- End Google Tag Manager --> <!-- Top Nav --> <nav class="navigation" role="navigation"> <div id="mega-menu" class="navbar navbar-inverse navbar-fixed-top"> <div class="navbar-inner"> <div class="container"> <a class="btn btn-navbar" data-toggle="collapse" data-target=".nav-collapse"> <span class="icon-bar"></span> <span class="icon-bar"></span> <span class="icon-bar"></span> </a> <div class="nav-collapse collapse"> <ul id="nav-joomla" class="nav"> <li class="dropdown"> <a class="dropdown-toggle" data-toggle="dropdown" href="#"> <span dir="ltr"><span aria-hidden="true" class="icon-joomla"></span> Joomla!<sup>®</sup></span> <span class="caret"></span> </a> <ul class="dropdown-menu"> <li> <a href="https://web.archive.org/web/20170628154843/https://www.joomla.org/"> <span aria-hidden="true" class="icon-joomla"></span> <span dir="ltr">Joomla!</span> Home </a> </li> <li class="divider"><span></span></li> <li class="nav-header"><span>Support <span dir="ltr">Joomla!</span></span></li> <li><a href="https://web.archive.org/web/20170628154843/https://www.joomla.org/contribute-to-joomla.html">Contribute</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://community.joomla.org/the-joomla-shop.html">The <span dir="ltr">Joomla!</span> Shop</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://www.joomla.org/sponsorship">Sponsorship</a></li> <li class="divider"><span></span></li> <li class="nav-header"><span>Try <span dir="ltr">Joomla!</span></span></li> <li><a href="https://web.archive.org/web/20170628154843/https://demo.joomla.org/">Demo</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://www.joomla.com/">Free Hosted Website</a></li> </ul> </li> <li class="dropdown"> <a class="dropdown-toggle" data-toggle="dropdown" href="#">About <span class="caret"></span></a> <ul class="dropdown-menu"> <li><a href="https://web.archive.org/web/20170628154843/https://www.joomla.org/about-joomla.html">About <span dir="ltr">Joomla!</span></a></li> <li><a href="https://web.archive.org/web/20170628154843/https://www.joomla.org/core-features.html">Core Features</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://www.joomla.org/about-joomla/the-project.html">The Project</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://www.joomla.org/about-joomla/the-project/leadership-team.html">Leadership</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://opensourcematters.org/">Open Source Matters</a></li> </ul> </li> <li class="dropdown"> <a class="dropdown-toggle" data-toggle="dropdown" href="#">Download & Extend <span class="caret"></span></a> <ul class="dropdown-menu"> <li><a href="https://web.archive.org/web/20170628154843/https://downloads.joomla.org/">Joomla! Downloads</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://extensions.joomla.org/">Extensions Directory</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://community.joomla.org/translations.html">Language Packages</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://showcase.joomla.org/">Showcase Directory</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://certification.joomla.org/">Certification Program</a></li> </ul> </li> <li class="dropdown"> <a class="dropdown-toggle" data-toggle="dropdown" href="#">News <span class="caret"></span></a> <ul class="dropdown-menu"> <li><a href="https://web.archive.org/web/20170628154843/https://www.joomla.org/announcements.html">Announcements</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://community.joomla.org/blogs.html">Blogs</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://magazine.joomla.org/">Magazine</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://community.joomla.org/connect.html"><span dir="ltr">Joomla!</span> Connect</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://www.joomla.org/mailing-lists.html">Mailing Lists</a></li> </ul> </li> <li class="dropdown"> <a class="dropdown-toggle" data-toggle="dropdown" href="#">Community <span class="caret"></span></a> <ul class="dropdown-menu"> <li><a href="https://web.archive.org/web/20170628154843/https://community.joomla.org/">Community Portal</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://community.joomla.org/events.html"><span dir="ltr">Joomla!</span> Events</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://tm.joomla.org/">Trademark & Licensing</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://community.joomla.org/user-groups.html">User Groups</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://showcase.joomla.org/">Showcase Directory</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://volunteers.joomla.org/">Volunteers Portal</a></li> </ul> </li> <li class="dropdown"> <a class="dropdown-toggle" data-toggle="dropdown" href="#">Support <span class="caret"></span></a> <ul class="dropdown-menu"> <li><a href="https://web.archive.org/web/20170628154843/https://forum.joomla.org/">Forum</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://docs.joomla.org/">Documentation</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://issues.joomla.org/">Issue Tracker</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://resources.joomla.org/">Resources Directory</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://community.joomla.org/joomla-training.html"><span dir="ltr">Joomla!</span> Training</a></li> </ul> </li> <li class="dropdown"> <a class="dropdown-toggle" data-toggle="dropdown" href="#">Developers <span class="caret"></span></a> <ul class="dropdown-menu"> <li><a href="https://web.archive.org/web/20170628154843/https://developer.joomla.org/">Developer Network</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://docs.joomla.org/">Documentation</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://docs.joomla.org/Bug_Squad">Bug Squad</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://developer.joomla.org/security.html">Security Centre</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://api.joomla.org/">API Documentation</a></li> <li><a href="https://web.archive.org/web/20170628154843/http://joomlacode.org/">JoomlaCode</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://framework.joomla.org/"><span dir="ltr">Joomla!</span> Framework</a></li> </ul> </li> </ul> <div id="nav-search" class="navbar-search pull-right"> <form id="mod-finder-searchform84" action="/web/20170628154843/https://developer.joomla.org/search.html" method="get" class="form-search"> <div class="finder"> <label for="mod-finder-searchword84" class="element-invisible finder">Search</label><input type="text" name="q" id="mod-finder-searchword84" class="search-query input-medium" size="20" value="" placeholder="Search ..."/> </div> </form> </div> </div> </div> </div> </div> </nav> <!-- Header --> <header class="header"> <div class="container"> <div class="row-fluid"> <div class="span7"> <h1 class="page-title"> <a href="/web/20170628154843/https://developer.joomla.org/">Joomla! Developer Network™</a> </h1> </div> <div class="span5"> <div class="btn-toolbar pull-right"> <div class="btn-group"> <a href="https://web.archive.org/web/20170628154843/https://downloads.joomla.org/" class="btn btn-large btn-warning">Download</a> </div> <div class="btn-group"> <a href="https://web.archive.org/web/20170628154843/https://demo.joomla.org/" class="btn btn-large btn-primary">Demo</a> </div> </div> </div> </div> </div> </header> <nav class="subnav-wrapper"> <div class="subnav"> <div class="container"> <ul class="nav menu nav-pills"> <li class="item-435 default"><a href="/web/20170628154843/https://developer.joomla.org/">Home</a></li><li class="item-465"><a href="/web/20170628154843/https://developer.joomla.org/news.html">News</a></li><li class="item-743"><a href="/web/20170628154843/https://developer.joomla.org/roadmap.html">Project Roadmap</a></li><li class="item-479 parent"><a href="/web/20170628154843/https://developer.joomla.org/cms.html">CMS</a></li><li class="item-478 parent"><a href="/web/20170628154843/https://developer.joomla.org/framework.html">Framework</a></li><li class="item-480 parent"><a href="/web/20170628154843/https://developer.joomla.org/tracker.html">Tracker</a></li><li class="item-482 parent"><a href="/web/20170628154843/https://developer.joomla.org/about.html">About</a></li><li class="item-516 current active"><a href="/web/20170628154843/https://developer.joomla.org/security.html">Security</a></li></ul> </div> </div> </nav> <!-- Body --> <div class="body"> <div class="container"> <div class="row-fluid"> <main id="content" class="span9"> <!-- Begin Content --> <div id="system-message-container"> </div> <div class="item-page" itemscope itemtype="https://schema.org/Article"> <meta itemprop="inLanguage" content="en-GB"/> <div class="page-header"> <h1> Joomla! Security Strike Team </h1> </div> <dl class="article-info muted"> <dt class="article-info-term"> </dt> <dd class="modified"> <span class="icon-calendar" aria-hidden="true"></span> <time datetime="2017-01-30T13:04:08+00:00" itemprop="dateModified"> Last Updated: 30 January 2017 </time> </dd> </dl> <div itemprop="articleBody"> <p class="lead">The Joomla! Project takes security vulnerabilities very seriously. As such, the Joomla! Security Strike Team (JSST) oversees the project's security issues and follows some specific procedures when dealing with these issues.</p> <h2>About the JSST</h2> <p><img class="pull-right" title="Joomla! Security Strike Team" src="/web/20170628154843im_/https://developer.joomla.org/images/joomla-security-strike-team.png" alt="Joomla Security Strike Team"/></p> <p>In wild land firefighting, the term "Strike Team" is used to describe a collection of similar resources, which used for a specific purpose (<a title="Strike Team" href="https://web.archive.org/web/20170628154843/https://en.wikipedia.org/wiki/Strike_Team">https://en.wikipedia.org/wiki/Strike_Team</a>). The JSST is called a strike team because it is a collection of developers and security experts tasked with improving and managing security for Joomla. The JSST roster can be found on the <a title="JSST on the Joomla! Volunteers Portal" href="https://web.archive.org/web/20170628154843/https://volunteers.joomla.org/teams/security-strike-team">Joomla! Volunteers Portal</a>.</p> <p>If you want to join the team send an email to <span id="cloakd6cb5dadd99c8077fd41dac4bab6b19f">This email address is being protected from spambots. You need JavaScript enabled to view it.</span><script type="text/javascript"> document.getElementById('cloakd6cb5dadd99c8077fd41dac4bab6b19f').innerHTML = ''; var prefix = 'ma' + 'il' + 'to'; var path = 'hr' + 'ef' + '='; var addyd6cb5dadd99c8077fd41dac4bab6b19f = 'security' + '@'; addyd6cb5dadd99c8077fd41dac4bab6b19f = addyd6cb5dadd99c8077fd41dac4bab6b19f + 'joomla' + '.' + 'org'; var addy_textd6cb5dadd99c8077fd41dac4bab6b19f = 'security' + '@' + 'joomla' + '.' + 'org';document.getElementById('cloakd6cb5dadd99c8077fd41dac4bab6b19f').innerHTML += '<a title="Email the JSST" ' + path + '\'' + prefix + ':' + addyd6cb5dadd99c8077fd41dac4bab6b19f + '\'>'+addy_textd6cb5dadd99c8077fd41dac4bab6b19f+'<\/a>'; </script> and ask for more details. Due to the sensitive nature of security work the team's membership is restricted, but we welcome anyone who is qualified to contact us about membership.</p> <h2>Reporting Procedures</h2> <p>If you find a possible vulnerability, please report it to the JSST <strong>first</strong>. You can contact the team via email at <span id="cloak9c54e92d349e91f4dc18a6904ab1756f">This email address is being protected from spambots. You need JavaScript enabled to view it.</span><script type="text/javascript"> document.getElementById('cloak9c54e92d349e91f4dc18a6904ab1756f').innerHTML = ''; var prefix = 'ma' + 'il' + 'to'; var path = 'hr' + 'ef' + '='; var addy9c54e92d349e91f4dc18a6904ab1756f = 'security' + '@'; addy9c54e92d349e91f4dc18a6904ab1756f = addy9c54e92d349e91f4dc18a6904ab1756f + 'joomla' + '.' + 'org'; var addy_text9c54e92d349e91f4dc18a6904ab1756f = 'security' + '@' + 'joomla' + '.' + 'org';document.getElementById('cloak9c54e92d349e91f4dc18a6904ab1756f').innerHTML += '<a title="Email the JSST" ' + path + '\'' + prefix + ':' + addy9c54e92d349e91f4dc18a6904ab1756f + '\'>'+addy_text9c54e92d349e91f4dc18a6904ab1756f+'<\/a>'; </script> or using the <a title="JSST Contact Form" href="/web/20170628154843/https://developer.joomla.org/security/contact-the-team.html">contact form</a> on this site.</p> <h3>Team Scope</h3> <p>The JSST operates with a limited scope and only directly responds to issues with the core Joomla! CMS and Framework, as well as processing reports regarding the *.joomla.org network of websites. We do not directly handle potential vulnerabilities with Joomla! extensions or websites built by our users, however there are resources available for these categories. The <a href="https://web.archive.org/web/20170628154843/https://vel.joomla.org/">Vulnerable Extensions List</a> contains reports of security vulnerabilities in extensions and users may seek assistance with security issues on their websites from the <a href="https://web.archive.org/web/20170628154843/https://forum.joomla.org/viewforum.php?f=714">Joomla! Forum</a>.</p> <h3>Requested Information</h3> <p>To be able to fully respond to a potential security issue, the JSST asks that issue reports includes as much of the following data as possible:</p> <ul> <li>The Joomla! software (CMS or Framework) or website (*.joomla.org) affected by the vulnerability (for the software, please include the version(s) tested)</li> <li>Steps to reproduce the problem <ul> <li>For the CMS or Framework, this should be what is required from a new install of the affected package</li> <li>For the *.joomla.org websites, this should be the steps taken to trigger the vulnerability</li> </ul> </li> <li>If sharing a vulnerability reported elsewhere, please include the source of this report</li> <li>A patch may be proposed which will be reviewed by the JSST</li> </ul> <h3>Response Handling</h3> <p>The JSST aims to ensure all issues are handled in a timely manner and for clear communication between the team and issue reporters. As such, we have established the following guidelines for responding to issue reports:</p> <ol> <li>Within 24 hours every report gets acknowledged</li> <li>Within 7 days every report gets a further response stating either <ol type="a"> <li>the issue is closed (and why)</li> <li>the issue is still under investigation; if needed, additional information will be requested</li> </ol> </li> <li>Within 21 days every report must be resolved unless there are exceptional circumstances requiring additional time</li> </ol> <h3>Signed & Encrypted Mail</h3> <p>We maintain <a href="/web/20170628154843/https://developer.joomla.org/security/gpg-keys.html">a list of GPG keys and addresses</a> for the <span id="cloak84068e9fbdfe68ee82480390c4545fa9">This email address is being protected from spambots. You need JavaScript enabled to view it.</span><script type="text/javascript"> document.getElementById('cloak84068e9fbdfe68ee82480390c4545fa9').innerHTML = ''; var prefix = 'ma' + 'il' + 'to'; var path = 'hr' + 'ef' + '='; var addy84068e9fbdfe68ee82480390c4545fa9 = 'security' + '@'; addy84068e9fbdfe68ee82480390c4545fa9 = addy84068e9fbdfe68ee82480390c4545fa9 + 'joomla' + '.' + 'org'; var addy_text84068e9fbdfe68ee82480390c4545fa9 = 'security' + '@' + 'joomla' + '.' + 'org';document.getElementById('cloak84068e9fbdfe68ee82480390c4545fa9').innerHTML += '<a ' + path + '\'' + prefix + ':' + addy84068e9fbdfe68ee82480390c4545fa9 + '\'>'+addy_text84068e9fbdfe68ee82480390c4545fa9+'<\/a>'; </script> address and members of the JSST to allow signed and encrypted communications.</p> <h2>Goals</h2> <ol> <li>Investigate and respond to reported vulnerabilities in the Joomla! CMS, Framework, and joomla.org websites.</li> <li>Execute code reviews prior to release to identify new vulnerabilities.</li> <li>Provide public presence regarding security issues.</li> <li>Help the community understand Joomla! security.</li> </ol> <h2>Security Announcement Policy</h2> <ul> <li>Verified vulnerabilities will only be publicly announced AFTER a release is issued which fixes the vulnerability.</li> <li>All announcements will contain as much information as possible, but will NOT contain step-by-step instructions for the vulnerability.</li> </ul> <h2>Public Responses Policy</h2> <p>Articles are written about Joomla! all the time. In many circumstances, these articles (even from reputable sources) contain a significant amount of misinformation.</p> <ul> <li>The JSST in conjunction with the <a href="https://web.archive.org/web/20170628154843/https://volunteers.joomla.org/teams/marketing">Marketing Team</a> will assess and address articles written about security issues <ul> <li>If the article contains valid information about a vulnerability not yet fixed, we will ask the publisher to suspend the article until we can fix the issue</li> <li>If the article contains invalid information, we will note what is invalid, and ask the publisher to either fix or remove the article</li> </ul> </li> <li>The JSST will be available to answer questions/validate any Joomla! security related articles on the publisher's request</li> </ul> <h2>Security Release Policy</h2> <ul> <li>Critical and high-level vulnerabilities trigger an immediate release cycle</li> <ul> <li>The Joomla! project may release an advisory indicating the scheduled release window to allow site owners to prepare for the release</li> </ul> <li>Moderate vulnerabilities may trigger a release cycle depending on the specific issue</li> <li>Low and very low vulnerabilities (and moderates which do not trigger a release cycle) will be included with the next scheduled maintenance release</li> <li>All security releases will be accompanied by one (or more) appropriate <a title="Joomla! Security Announcements" href="/web/20170628154843/https://developer.joomla.org/security-centre.html">security announcements</a></li> </ul> <h3>Issue Credit</h3> <p>The Joomla! project will properly credit individuals and/or organizations who responsibly disclose security issues to the JSST. You can indicate the way you would like to be referred to in the advisory about the vulnerability. Our preference is to use full names. If you do not specify then we will use the contact name associated with the email address the report was received from. You can also request a pseudonym or having your name withheld.</p> <h2>Vulnerability Threat Levels</h2> <p>In accordance with the <a title="Joomla! Development Strategy" href="/web/20170628154843/https://developer.joomla.org/cms/development-strategy.html#security_policy">security policy</a> from the Joomla! project's development strategy, there are two main details that contribute to a vulnerability's priority or "threat level":</p> <h3>Impact</h3> <table class="table table-bordered table-striped"> <thead> <tr> <th>Level</th> <th>Description</th> </tr> </thead> <tbody> <tr> <td>Critical</td> <td>“0-day" attacks, and attacks where site control is compromised (allows attacker to take control of the site).</td> </tr> <tr> <td>High</td> <td>SQL injection attacks, remote file include attacks, and other attack vectors where site data is compromised.</td> </tr> <tr> <td>Moderate</td> <td>XSS attacks, write ACL violations (editing or creating of content where not allowed).</td> </tr> <tr> <td>Low</td> <td>Read ACL violations (reading of content where not allowed).</td> </tr> </tbody> </table> <h3>Severity</h3> <table class="table table-bordered table-striped"> <thead> <tr> <th>Level</th> <th>Description</th> <th>Release Fix</th> </tr> </thead> <tbody> <tr> <td>Critical</td> <td>VERY easy to perform. Relies on no outside information (TRUE 0-day attack).</td> <td>As soon as possible</td> </tr> <tr> <td>High</td> <td>Moderately easy to perform. May rely on readily available outside information.</td> <td>Per oCERT guidelines</td> </tr> <tr> <td>Moderate</td> <td>Not easy to perform. May rely on sensitive information.</td> <td>Per oCERT guidelines</td> </tr> <tr> <td>Low</td> <td>Difficult to perform. Relies on sensitive information or requires special circumstances to perform.</td> <td>Per oCERT guidelines</td> </tr> </tbody> </table> <p><strong>NOTE:</strong> The descriptions are just generic guidelines. Each vulnerability will be assessed for damage potential and will be ranked accordingly.</p> <h2>Supported Versions</h2> <p>All currently developed and supported versions of the Joomla! CMS and Framework will be actively monitored by the JSST.</p> <p>Currently active versions include:</p> <ul> <li>Joomla! CMS - 3.x</li> <li>Joomla! Framework - 1.x</li> </ul> </div> </div> <ul itemscope itemtype="http://schema.org/BreadcrumbList" class="breadcrumb"> <li class="active"> You are here:   </li> <li itemprop="itemListElement" itemscope itemtype="http://schema.org/ListItem"> <a itemprop="item" href="/web/20170628154843/https://developer.joomla.org/" class="pathway"> <span itemprop="name"> Home </span> </a> <span class="divider"> / </span> <meta itemprop="position" content="1"> </li> <li itemprop="itemListElement" itemscope itemtype="http://schema.org/ListItem" class="active"> <span itemprop="name"> Security </span> <meta itemprop="position" content="2"> </li> </ul> <!-- End Content --> </main> <aside class="span3"> <!-- Begin Right Sidebar --> <div class="moduletable"> <div class="custom"> <h3>Joomla! CMS</h3> <div> <p><a href="https://web.archive.org/web/20170628154843/https://downloads.joomla.org/latest">Current Release</a> <span class="pull-right"><img src="/web/20170628154843im_/https://developer.joomla.org/images/compat_30.png" alt="Joomla! 3 Badge"/></span></p> <div class="alert">View known <a class="alert-link" href="https://web.archive.org/web/20170628154843/https://issues.joomla.org/">Issues</a></div> <p><a class="btn btn-medium" href="https://web.archive.org/web/20170628154843/https://github.com/joomla/joomla-cms#build-status" target="_blank">Development Status</a></p> <div class="alert"><a class="alert-link" href="/web/20170628154843/https://developer.joomla.org/nightly-builds.html">Nightly builds</a> are available for download</div> </div> <h3>Joomla! Framework</h3> <div> <p><a href="https://web.archive.org/web/20170628154843/https://framework.joomla.org/">Current Release</a><span class="pull-right"><img src="https://web.archive.org/web/20170628154843im_/https://avatars2.githubusercontent.com/u/6124926?v=3&s=200" alt="Joomla! Framework Logo" width="22" height="22"/> <strong>1.1.0</strong></span></p> <p><a class="btn btn-medium" href="https://web.archive.org/web/20170628154843/https://framework.joomla.org/status">Development Status</a></p> </div></div> </div> <div class="moduletable"> <h3>Resources</h3> <ul class="nav menu nav-stacked nav-tabs"> <li class="item-474"><a href="/web/20170628154843/https://developer.joomla.org/development-strategy.html">Development Strategy</a></li><li class="item-565"><a href="/web/20170628154843/https://developer.joomla.org/security-centre.html">Security Announcements</a></li><li class="item-736"><a href="/web/20170628154843/https://developer.joomla.org/security/contact-the-team.html">Report Security Issues</a></li><li class="item-685"><a href="/web/20170628154843/https://developer.joomla.org/about/stats.html">Usage Statistics</a></li><li class="item-687"><a href="/web/20170628154843/https://developer.joomla.org/about/stats/api.html">Statistics API Documentation</a></li><li class="item-466"><a href="https://web.archive.org/web/20170628154843/https://api.joomla.org/">Joomla! API Documentation</a></li><li class="item-467"><a href="/web/20170628154843/https://developer.joomla.org/coding-standards.html">Coding Standards Manual</a></li><li class="item-735"><a href="/web/20170628154843/https://developer.joomla.org/en-gb-user-interface-text-guidelines.html">en-GB User Interface Text Guidelines</a></li><li class="item-523"><a href="/web/20170628154843/https://developer.joomla.org/cms-coverage">CMS Code Coverage</a></li><li class="item-570"><a href="https://web.archive.org/web/20170628154843/https://framework.joomla.org/status">Framework Code Coverage</a></li><li class="item-662"><a href="/web/20170628154843/https://developer.joomla.org/joomlacode-archive.html">JoomlaCode Archive</a></li><li class="item-489"><a href="/web/20170628154843/https://developer.joomla.org/contribute.html">Contributing to Joomla!</a></li></ul> </div> <div class="moduletable"> <h3>Mailing Lists</h3> <ul class="nav menu nav-stacked nav-tabs"> <li class="item-748"><a href="/web/20170628154843/https://developer.joomla.org/newsletter.html">Developer Network Newsletter</a></li><li class="item-469"><a href="https://web.archive.org/web/20170628154843/https://groups.google.com/group/joomla-dev-general"> General Extensions Mailing</a></li><li class="item-470"><a href="https://web.archive.org/web/20170628154843/https://groups.google.com/group/joomla-dev-cms">CMS Mailing</a></li><li class="item-471"><a href="https://web.archive.org/web/20170628154843/https://groups.google.com/group/joomla-dev-framework">Framework Mailing</a></li><li class="item-514"><a href="https://web.archive.org/web/20170628154843/https://groups.google.com/group/joomla-docs">Documentation Mailing</a></li></ul> </div> <div class="custom"> <p class="center"><a title="Joomla! Training" href="https://web.archive.org/web/20170628154843/https://community.joomla.org/joomla-training.html"> <img src="/web/20170628154843im_/https://developer.joomla.org/images/banners/joomla-training.png" alt="Learn Joomla"/></a></p></div> <div class="custom"> <p class="center"><a title="Joomla! 3.7" href="https://web.archive.org/web/20170628154843/https://www.joomla.org/3/"> <img src="/web/20170628154843im_/https://developer.joomla.org/images/joomla-37.jpg" alt="joomla 3.7"/></a></p></div> <div class="moduletable"> <div class="custom"> <p class="center"><a title="Joomla World Conference 2017 | November 17 - 19 2017, Rome, Italy" href="https://web.archive.org/web/20170628154843/https://conference.joomla.org/" target="_blank" rel="noopener noreferrer"> <img src="/web/20170628154843im_/https://developer.joomla.org/images/banners/joomla-world-conference-2017.png" alt="joomla world conference 2017"/></a></p></div> </div> <!-- End Right Sidebar --> </aside> </div> </div> </div> <!-- Footer --> <footer class="footer center"> <div class="container"> <hr/> <div class="social"> <ul class="soc"> <li><a href="https://web.archive.org/web/20170628154843/https://twitter.com/joomla" target="_blank" class="soc-twitter2" title="Joomla! on Twitter"><span class="element-invisible">Joomla! on Twitter</span></a></li> <li><a href="https://web.archive.org/web/20170628154843/https://www.facebook.com/joomla" target="_blank" class="soc-facebook" title="Joomla! on Facebook"><span class="element-invisible">Joomla! on Facebook</span></a></li> <li><a href="https://web.archive.org/web/20170628154843/https://plus.google.com/+joomla/posts" target="_blank" class="soc-google" title="Joomla! on Google+"><span class="element-invisible">Joomla! on Google+</span></a></li> <li><a href="https://web.archive.org/web/20170628154843/https://www.youtube.com/user/joomla" target="_blank" class="soc-youtube3" title="Joomla! on YouTube"><span class="element-invisible">Joomla! on YouTube</span></a></li> <li><a href="https://web.archive.org/web/20170628154843/https://www.linkedin.com/company/joomla" target="_blank" class="soc-linkedin" title="Joomla! on LinkedIn"><span class="element-invisible">Joomla! on LinkedIn</span></a></li> <li><a href="https://web.archive.org/web/20170628154843/https://www.pinterest.com/joomla" target="_blank" class="soc-pinterest" title="Joomla! on Pinterest"><span class="element-invisible">Joomla! on Pinterest</span></a></li> <li><a href="https://web.archive.org/web/20170628154843/https://github.com/joomla" target="_blank" class="soc-github3 soc-icon-last" title="Joomla! on GitHub"><span class="element-invisible">Joomla! on GitHub</span></a></li> </ul> </div> <div class="footer-menu"> <ul class="nav-inline"> <li><a href="https://web.archive.org/web/20170628154843/https://www.joomla.org/"><span>Home</span></a></li> <li><a href="https://web.archive.org/web/20170628154843/https://www.joomla.org/about-joomla.html"><span>About</span></a></li> <li><a href="https://web.archive.org/web/20170628154843/https://community.joomla.org/"><span>Community</span></a></li> <li><a href="https://web.archive.org/web/20170628154843/https://forum.joomla.org/"><span>Forum</span></a></li> <li><a href="https://web.archive.org/web/20170628154843/https://extensions.joomla.org/"><span>Extensions</span></a></li> <li><a href="https://web.archive.org/web/20170628154843/http://resources.joomla.org/"><span>Resources</span></a></li> <li><a href="https://web.archive.org/web/20170628154843/https://docs.joomla.org/"><span>Docs</span></a></li> <li><a href="https://web.archive.org/web/20170628154843/https://developer.joomla.org/"><span>Developer</span></a></li> <li><a href="https://web.archive.org/web/20170628154843/https://community.joomla.org/the-joomla-shop.html"><span>Shop</span></a></li> </ul> <ul class="nav-inline"> <li><a href="https://web.archive.org/web/20170628154843/https://www.joomla.org/accessibility-statement.html">Accessibility Statement</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://www.joomla.org/privacy-policy.html">Privacy Policy</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://crowdin.com/projects/Joomla">Help Translate</a></li> <li><a href="https://web.archive.org/web/20170628154843/https://github.com/joomla/joomla-websites/issues/new?title=[jdev]%20&body=Please%20describe%20the%20problem%20or%20your%20issue">Report an Issue</a></li> <li><a href="/web/20170628154843/https://developer.joomla.org/login.html">Log in</a></li> </ul> <p class="copyright">© 2005 - 2017 <a href="https://web.archive.org/web/20170628154843/http://opensourcematters.org/">Open Source Matters, Inc.</a> All Rights Reserved.</p> <div class="hosting"> <div class="hosting-image"><a href="https://web.archive.org/web/20170628154843/https://www.rochen.com/joomla-hosting" target="_blank"><img class="rochen" src="https://web.archive.org/web/20170628154843im_/https://cdn.joomla.org/rochen/rochen_footer_logo_white.png" alt="Rochen"/></a></div> <div class="hosting-text"><a href="https://web.archive.org/web/20170628154843/https://www.rochen.com/joomla-hosting" target="_blank"><span dir="ltr">Joomla!</span> Hosting by Rochen</a></div> </div> </div> <div id="adblock-msg" class="navbar navbar-fixed-bottom hide"> <div class="navbar-inner"> <a class="close" data-dismiss="alert" href="#">×</a> <i class="icon-warning"></i> We have detected that you are using an ad blocker. The Joomla! Project relies on revenue from these advertisements so please consider disabling the ad blocker for this domain. </div> </div> </div> </footer> </body> </html> <!-- FILE ARCHIVED ON 15:48:43 Jun 28, 2017 AND RETRIEVED FROM THE INTERNET ARCHIVE ON 04:22:43 Feb 27, 2025. JAVASCRIPT APPENDED BY WAYBACK MACHINE, COPYRIGHT INTERNET ARCHIVE. ALL OTHER CONTENT MAY ALSO BE PROTECTED BY COPYRIGHT (17 U.S.C. SECTION 108(a)(3)). --> <!-- playback timings (ms): captures_list: 0.564 exclusion.robots: 0.031 exclusion.robots.policy: 0.018 esindex: 0.01 cdx.remote: 4.739 LoadShardBlock: 136.365 (3) PetaboxLoader3.datanode: 87.263 (4) PetaboxLoader3.resolve: 97.436 (2) load_resource: 103.027 -->