CVE-2021-23128: [20210302] - Core - Potential Insecure FOFEncryptRandval
An issue was discovered in Joomla! 3.2.0 through 3.9.24. The core shipped but unused randval implementation within FOF (FOFEncryptRandval) used an potential insecure implemetation. That has now been replaced with a call to 'randombytes()' and its backport that is shipped within randomcompat.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Joomla issue?
The vulnerability ID for this Joomla issue is CVE-2021-23128.
What is the severity of CVE-2021-23128?
The severity of CVE-2021-23128 is critical with a severity value of 9.1.
Which version of Joomla is affected by this vulnerability?
Joomla versions 3.2.0 through 3.9.24 are affected by this vulnerability.
How was the potential insecure implementation in FOF (FOFEncryptRandval) fixed?
The potential insecure implementation in FOF (FOFEncryptRandval) was replaced with a call to 'random_bytes()' and its backport that is shipped within random_compat.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the Joomla security center website: [https://developer.joomla.org/security-centre/842-20210302-core-potential-insecure-fofencryptrandval.html](https://developer.joomla.org/security-centre/842-20210302-core-potential-insecure-fofencryptrandval.html)