CVE-2020-35611: [20201102] - Core - Disclosure of secrets in Global Configuration page
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the current values.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-35611?
CVE-2020-35611 is a vulnerability discovered in Joomla! versions 2.5.0 through 3.9.22 that exposes secrets in the global configuration page.
How does CVE-2020-35611 affect Joomla!?
CVE-2020-35611 affects Joomla! versions 2.5.0 through 3.9.22, allowing secrets to be disclosed in the HTML output of the global configuration page.
What is the severity of CVE-2020-35611?
CVE-2020-35611 has a severity score of 7.5, indicating a high level of vulnerability.
How can I fix CVE-2020-35611?
To fix CVE-2020-35611, users should update Joomla! to a version beyond 3.9.22, where the vulnerability has been patched.
Where can I find more information about CVE-2020-35611?
More information about CVE-2020-35611 can be found in the Joomla! security advisory: https://developer.joomla.org/security-centre/829-20201102-core-disclosure-of-secrets-in-global-configuration-page.html