- Project: Joomla!
- SubProject: CMS
- Impact: Low
- Severity: Low
- Versions: 3.2.0 - 3.9.24
- Exploit type: Insecure Randomness
- Reported Date: 2021-01-12
- Fixed Date: 2021-03-02
- CVE Number: CVE-2021-23126, CVE-2021-23127
Usage of the insecure rand() function within the process of
generating the 2FA secret.
Usage of an insufficient length for the 2FA secret accoring to RFC 4226 of 10 bytes vs 20 bytes.
This issue has been coordinated with Akeeba Ltd as contributor of the original FOF codebase to the core.
Joomla! CMS versions 3.2.0 - 3.9.24
Upgrade to version 3.9.25
The JSST at the Joomla! Security Centre....
Read more https://developer.joomla.org/security-centre/841-20210301-core-insecure-randomness-within-2fa-secret-generation.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+JoomlaSecurityNews+%28Joomla%21+Security+News%29