Possible database leak of the Joomla project user base

Developers of the open content management system Joomla warned about the discovery of full backups of the website resources.joomla.org being stored in a third-party repository, including the user database of the JRD (Joomla Resources Directory).

The backups were not encrypted and included data about 2,700 users registered on the resources.joomla.org site, which collects information about developers and providers creating websites based on Joomla. In addition to publicly available personal data, the database contained information regarding password hashes, unpublished records, and IP addresses. All users registered in the JRD directory are advised to change their passwords and review potential password duplication across other services.

The backup was stored by a project participant in a third-party repository on Amazon Web Services S3, owned by a company founded by a former leader of the administrator team JRD, who remained among the developers at the time of the incident. The investigation of the incident is still ongoing, and it is not clear whether the backup fell into third-party hands. However, an audit conducted after the incident showed that there were accounts with administrative rights on the server resources.joomla.org that did not belong to employees of Open Source Matters, the company maintaining the Joomla project (it is not specified how these individuals are connected to the project).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster