Security Advisory

CVE-2021-23128

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-03-04 17:37:14
Last updated 2026-02-25 05:04:49
Assigner Joomla
State PUBLISHED

Description

An issue was discovered in Joomla! 3.2.0 through 3.9.24. The core shipped but unused randval implementation within FOF (FOFEncryptRandval) used an potential insecure implemetation. That has now been replaced with a call to random_bytes() and its backport that is shipped within random_compat.