Critical Security Vulnerability: Why Are We Still Waiting For A Fix? - Question | JoomShaper

Critical Security Vulnerability: Why Are We Still Waiting For A Fix?

Steve

Steve

General 1 week ago

Hello Joomshaper-Team

Unfortunately, I can only agree with all the other posts in the various threads on this topic.

About a month ago, I already shared my thoughts here in the forum regarding the – to put it mildly – “leaving room for improvement” handling of the security vulnerabilities in PageBuilder and Helix at that time: https://www.joomshaper.com/forum/question/45651

I received positive feedback from JoomShaper in response, which gave me hope that the handling of such security incidents would be reevaluated in the future.

Now four weeks have passed and unfortunately, NOTHING has changed with the next security incident. I have absolutely no understanding of why version 6.7.2 which would initially address only the security vulnerability hasn’t been released long ago.

I manage more than 60 client websites using SP Page Builder and have been waiting since yesterday by checking for updates nearly every hour for this version to be released. Even more problematic is the announcement that the update was supposed to be released "very soon." Trusting that, I initially refrained from securing all client sites with the manual workaround. I had to catch up on that today, since far too much time has passed by now.

Hence my serious question to JoomShaper: WHY?

Why are you making your customers – including agencies responsible for dozens of client websites – wait in a situation like this, thereby forcing them to leave their websites unprotected despite a known critical security vulnerability for several days?

What if websites have already been compromised? With a known critical security vulnerability, every hour counts! In a situation like this, none of your clients care whether the new version also includes possibly additional features or bug fixes.

Please release the security fix. Immediately. Everything else can come AFTER that.

Following this latest incident, I’ve now reached a point where I’m seriously considering implementing future projects with other providers and gradually phasing out JoomShaper.

After many years of collaboration, this is not a decision I’m considering lightly. But in my view, handling critical security vulnerabilites in this manner is simply unprofessional.

It’s stressful. It takes time. And ultimately, it costs money especially if such handling leads to further and possibly even greater damage.

With disappointed regards, Steve

0
8 Answers
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 week ago #231682

Hi Steve, a new version was published 30 min ago.

I talked with the team, to publish security updates sooner, before all "extras". I fully understand your side. Hopefully if you had firewall component installed, it could protect you from last "article hole". I got that confirmation from 3 different J! firewall developers.

0
Ziaul Kabir
Ziaul Kabir
Accepted Answer
Support Agent 1 week ago #231683

Hi Steve,

Thank you for sharing your concerns, and we completely understand your frustration, especially when you’re managing a large number of client websites. We sincerely apologize for the inconvenience and concern this situation has caused.

The security improvements are now included in SP Page Builder v6.8.0. Could you please update to the latest version and check on your websites?

We truly appreciate your patience and continued trust in JoomShaper. 🙏

Best regards,

0
D
David Forés
Accepted Answer
1 week ago #231684

They've already released the new version.

I agree with everything you say. The truth is, it's hard to explain.

The only explanation I can think of is that they didn't want to release two versions on two consecutive days or within the same week, in case their customers got “upset” about having to update so frequently. But we’ve seen it happen more than once: they release a version, and a few hours later they release another one because there was a major bug. And this could happen now too, since they were in a rush to release 6.8.0, they might not have done thorough testing, and tomorrow we’ll see 6.8.1 fixing some bug. It can happen.

Even the leader of Joomla’s security team had to chime in here to ask, “What are you doing?” and remind them of the main security rules, including the one we’ve repeatedly emphasized here to clients, that a critical update (hypothetical version 6.7.2) should have been released immediately and as a standalone update separate from other bug fixes and new features.

I’ve already made up my mind. Even though my subscription is paid through November 2029, my medium-term goal is to stop using these tools and improve my well-being.

1
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 week ago #231685

Hi David,

As I said above, the security update process has to be changed from our side, like other software has. Times when we could wait (a day longer) ended. How every kid can be AI hacker. And because EU govement don't do anything with that we all pay the price.

0
AB
Andreas Becker
Accepted Answer
1 week ago #231693

Everyone is having problems right now, and many security vulnerabilities that have been around for a long time are just now being exposed.

I just wonder why they aren't focusing on finding security vulnerabilities and making the software more secure. Instead, they're rolling out new features again.

I think for 99% of people, that's the top priority. Whether a new feature comes out in 1 month or 4 months doesn't really matter.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 week ago #231697

I just wonder why they aren't focusing on finding security vulnerabilities and making the software more secure.

Becuase it's not fully possible in OpenSource code. WordPress has exactly the same problem, but on huge scale. AI created a new possibilites.


Year ago, Louvre in Paris (France) was robbed (in 8 min) they took Crown Jewels, with all the high-tech and guards they had. As you see, nothing is safe now. And your expensive car, no problem, probably less than a minute. Suprised?

0
AB
Andreas Becker
Accepted Answer
1 week ago #231716

Can’t we fully focus on security just because it’s open source? Of course, after the last two months, security can be the top priority.

And just because you can’t prevent everything, you can still make it as difficult as possible for attackers. And, of course, try to find bugs before the attackers do.

I don’t understand this apparent resignation along the lines of, “Yeah, you can break into a museum or steal a car, too.”

P.S.: I’m not saying that’s actually the case, but as an outsider, that’s how it feels.

1
A
Addington
Accepted Answer
1 week ago #231720

I think no one is asking: why don't you make your extensions and templates 100% secure? The question is: why don't you put new features on the backburner and focus on making your extensions as secure as possible?

2