Joomla 4.2.1 Released
The Joomla! Project is delighted to announce a security release for 4.x series of Joomla which addresses a security vulnerability and contains various bug fixes and improvements
This release continues Joomla 4’s high standards in accessible web design and brings exciting new features, highlighting Joomla's values of inclusiveness, simplicity and security into an even more powerful open-source web platform.
With Joomla 4.2.1, we have new and improved features for bloggers and authors, web designers, extension developers and web agencies.
The highlights are:
With the new keyboard shortcuts, you can save time and become more productive.
There are 9 built into the administrator side of your site such as J + F to jump into the search field or J + S to save
And the great news is that other extensions are able to add their own shortcuts as well. Pressing J + X to get a list of them all. The keystrokes are all sequential, making it more accessible than hitting them simultaneously.
Until now, Joomla only offered ‘Two-Factor’ Authentication; with ‘Multi-factor’ Authentication, we are taking site access security one step further by allowing you to choose different authentication mechanisms to secure your site. You can choose to use a Yubi-key, Web Authentication, a verification code, or a code by email.
The way Multi-factor Authentication works is that you first log in with your username and password. After that, you are presented with another screen to enter your second authentication method.
This means that you will no longer be able to enter your two-factor authentication code on the same page as the login page.
Security Issues Fixed
 Low Severity - Low Impact - Multiple Full Path Disclosures because of missing '_JEXEC or die check' (affecting Joomla! 4.2.0)
Bug fixes and Improvements with 4.2.1
- Failure in setting Redis cache
- Change the db calls back to the getDbo
- Error when Gather Statistic enabled in Smart Search
- Fixed menu login with redirect to menu item on multi-language site
- Add bcmath_compat polyfill for servers without BCmath / GMP support
- Remove unused imports in Multi-factor Authentication
- Fix issue "updateCheck is null"
- Remove hotkeys.js as they have been renamed
- Stats collection must not be shown in captive MFA pages
- CLI application crashed when MVCFactory is used
- Correctly revert pull request no. 38244 for updating from 4.2.0 RC 1
Visit GitHub for the full list of bug fixes.
Click here for full release information.
We are familiar with the implementation of the upgrade and are currently upgrading multiple sites CONTACT US for a free proposal to update your site.