SECURITY UPDATE For EasyStore - V2.0.2 - Question | JoomShaper

SECURITY UPDATE For EasyStore - V2.0.2

SC

Stuart Clark

EasyStore 2 weeks ago

There have been 3 security issues found in EasyStore, which have all now been fixed in version 2.0.2.

Unfortunately, JoomShaper FAILED to admit that this update is an important security update!

More info can be found here - https://mysites.guru/blog/easystore-security-disclosure/

0
5 Answers
D
David Forés
Accepted Answer
2 weeks ago #229969

I don't understand how a security update can be bundled with various bugs and other improvements.

Sometimes I get the feeling that no one is at the helm of this ship and it’s just drifting aimlessly...

There you have it: several open tickets with complaints that version 2.0.2 “breaks everything,” and immediately, a new emergency release (2.0.3) is published to patch a version that hadn’t been tested thoroughly enough and that mixed too many things together.

0
Ziaul Kabir
Ziaul Kabir
Accepted Answer
Support Agent 2 weeks ago #230011

Hello,

Thank you for your feedback.

The security issues reported were addressed in EasyStore 2.0.2. The follow-up release, EasyStore 2.0.3, was published to fix layout-related issues that some users experienced after updating to 2.0.2. These layout issues were not related to the security fixes themselves.

We appreciate your feedback and will work on communicating important security updates more clearly in future release notes.

Thank you.

0
SC
Stuart Clark
Accepted Answer
2 weeks ago #230014

The significant point here, which is being IGNORED, is that 2.0.2 CLEARLY WASN'T PROPERLY TESTED BEFORE BEING RELEASED

Thus, you caused YET MORE disruption for your customers, who have ALREADY had to apply numerous SECURITY PATCHES for other BUGS in your code - and yet you show ZERO care for what those customers have had to go through, purely due to your poor coding quality!

1
D
David Forés
Accepted Answer
2 weeks ago #230023

That's exactly what I'm referring to, what you just confirmed:

These layout issues were not related to the security fixes themselves.

A security update—especially one like this with more than one critical vulnerability—should not be bundled with other bug-fix updates, let alone updates introducing new features.

The top priority is ensuring stability, and if it’s a “mandatory” update, the changes should be kept to the bare minimum.

I hope this message isn’t taken as an attack, since in recent weeks I’ve seen some pretty harsh comments—the result of desperation from users who’ve had their websites attacked and don’t know how to fix the problem. Rather, I hope it’s seen as constructive criticism and a call for improvement.

We’ve all had a very intense few weeks—both on your end, resolving security issues and handling hundreds of support tickets, and on our end, thoroughly reviewing each of our websites.

To summarize, and as I’ve reiterated before, given the current circumstances, urgent updates should be kept to the bare minimum, while other improvements and fixes can certainly wait a few days and be thoroughly tested before being released.

0
Ziaul Kabir
Ziaul Kabir
Accepted Answer
Support Agent 2 weeks ago #230027

Hi Stuart and David,

Thank you both for taking the time to share your thoughts. We genuinely appreciate the candid feedback.

We understand the frustration caused by having to apply multiple urgent updates in a short period of time. Security releases are stressful for everyone involved, and we recognize that any issues following an update can add to that burden.

David, thank you for clearly explaining your perspective. Your point about keeping urgent security releases as minimal as possible is well taken. We agree that stability is critical, especially when customers are updating under pressure. We'll continue reviewing our release process to better separate urgent security fixes from other non-essential changes whenever possible.

Stuart, we also understand your concerns regarding testing. While EasyStore 2.0.2 resolved the reported security vulnerabilities, the subsequent layout issues experienced by some users showed that our validation process can be improved. We're taking that feedback seriously and are reviewing how we test releases to reduce the likelihood of similar issues in the future.

We know the past few weeks have been difficult for many customers, and we appreciate everyone who has provided constructive feedback while working through these updates.

Our goal is to learn from this experience and improve both our release process and our communication going forward.

Thank you again for your patience and for helping us improve.

0