First published: Thu Mar 04 2021(Updated: )
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of the insecure rand() function within the process of generating the 2FA secret.
Credit: security@joomla.org security@joomla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla Joomla\! | >=3.2.0<3.9.25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23126 is a vulnerability in Joomla! versions 3.2.0 through 3.9.24 that allows the usage of the insecure rand() function during the generation of 2FA secrets.
CVE-2021-23126 affects Joomla! versions 3.2.0 through 3.9.24 by allowing the usage of the insecure rand() function during the generation of 2FA secrets.
The severity of CVE-2021-23126 is medium with a CVSS score of 5.3.
To fix CVE-2021-23126 in Joomla!, upgrade to version 3.9.25 or later.
More information about CVE-2021-23126 can be found on the Joomla! Security Centre website at https://developer.joomla.org/security-centre/841-20210301-core-insecure-randomness-within-2fa-secret-generation.html.