This release only contains the security fix; no other changes have been made compared to the Joomla! 4.2.7 release.
After the release, we strongly advise you to renew the passwords for all credentials that are stored in the global site configuration, namely:
- database
- SMTP
- Redis
- HTTP proxy
The issue has been reported in a responsible disclosure process, there have been no signs of exploitation on public sites.
Security issue fixed with 4.2.8
[20230201] - Core - Improper access check in webservice endpoints
For New Installations
New installation instructions and technical requirements
For Upgrade an installation