J3.x

Joomla 3.8.13 Security Notes/de: Difference between revisions

From Joomla! Documentation

Created page with "de"
 
Created page with "Ab 3.8.13 stellt Joomla den Prozess der Genehmigung eines Benutzers nach einer E-Mail-Benachrichtigung sicher, indem es den Administrator, der die Anfrage genehmigen soll, auf..."
Line 5: Line 5:


[[Image:3813-email-notification-de.png|800px]]
[[Image:3813-email-notification-de.png|800px]]
As of 3.8.13, Joomla is securing the process on approving an user after an email notification by requesting the administrator, who is going to approve the request, to login into the frontend. After the administrator logged in, they are redirected to the activation URL and the account is activated. The main reason is that we have got some reports on "auto approvings", done by antivirus software checking any URL send by email.
Ab 3.8.13 stellt Joomla den Prozess der Genehmigung eines Benutzers nach einer E-Mail-Benachrichtigung sicher, indem es den Administrator, der die Anfrage genehmigen soll, auffordert, sich am Frontend anzumelden. Nachdem sich der Administrator angemeldet hat, wird er auf die Aktivierungs-URL weitergeleitet und das Konto wird aktiviert. Der Hauptgrund dafür ist, dass wir einige Meldungen über automatische Freigaben erhalten haben, die von Antivirensoftware erstellt wurden, die jede per E-Mail versendete URL überprüft hat.
 
Übersetzt mit www.DeepL.com/Translator


=== Improved security for the Joomla Update Component ===
=== Improved security for the Joomla Update Component ===

Revision as of 14:21, 9 October 2018

Joomla 3.8.13 Security Notes

New ACL Verification on approving an user after email notification

File:3813-email-notification-de.png Ab 3.8.13 stellt Joomla den Prozess der Genehmigung eines Benutzers nach einer E-Mail-Benachrichtigung sicher, indem es den Administrator, der die Anfrage genehmigen soll, auffordert, sich am Frontend anzumelden. Nachdem sich der Administrator angemeldet hat, wird er auf die Aktivierungs-URL weitergeleitet und das Konto wird aktiviert. Der Hauptgrund dafür ist, dass wir einige Meldungen über automatische Freigaben erhalten haben, die von Antivirensoftware erstellt wurden, die jede per E-Mail versendete URL überprüft hat.

Übersetzt mit www.DeepL.com/Translator

Improved security for the Joomla Update Component

As of 3.8.13, Joomla is locking down the Joomla Update Component to Super Administrators only, as this component is by design intended to apply changes to the core of the CMS and by also processes sensitive data related to site updates. Therefore we decided that this component and its feature should be restricted to Super Administrators only.