"Security is an ongoing journey: The best way to stay safe is to always stay up-to-date" says Beat (CB Team and JSST - Joomla Security Strike Team member).
The previous Joomla 3.4.6 critical security release triggered an in depth security investigation by the JSST Team to better understand the true nature and cause of this vulnerability.
This "follow the code" process has identified the root cause of this issue down to a specific PHP security bug, already fixed on 4th September 2015 in PHP 5.4.45, 5.5.29 and 5.6.13 (and also in all PHP 7 releases) and also in all major Linux distributions back in September 2015
In an effort to help secure Joomla against poorly maintained hosting environments, the Joomla project has released Joomla 3.4.7 along with Joomla 2.5 and 1.5 code fixes.
This is really important! If you are reading this, you should stop what you are doing and start updating/patching all your websites now.
There is no need to delay. The Joomla 3.4.6 package only addresses the vulnerabilities and will not break anything you have installed upgrading from 3.4.5 to 3.4.6 (including of course Community Builder 2.0.12).
If your website is not patched and your hosting does not have proper security counter-measures (btw - our hosting has already blocked thousands of attackers), you are at risk - protect your websites now !
So here is a list of steps to help you quickly get started:
Upgrade to latest CB 2.0.11 Nightly release
Download the CB GroupJive 3.0 beta one distribution
Unzip distribution package to reveal individual CB plugins, Joomla module and Joomla plugin
Install the CB Plugins using the CB Plugin Manager and then publish them
Optionally Install Joomla module and Joomla search plugin and publish
Create a new Joomla menu (give it a name like GroupJive) of menu type Community Builder -> Plugin Select CB GroupJive from Plugin dropdown and save Then Select All Categories in the Action parameter Save menu
Create as many categories as you want from the CB GroupJive -> Categories button
You can also create groups from the CB GroupJive -> Groups button
Access GroupJive from your website frontend by clicking on the Joomla menu you created in step 6
You can explore options and settings to quickly get the hang of things and study all available tooltips. We are working on a GroupJive Primer Book that should be available when release candidate status is reached,
Please post any problems or feedback on the discussion thread below so we can quickly address and fix. Depending on feedback and issues identified we will be issuing either a new beta release or we will be going directly to a Release Candidate process.
The aftermath comments like "great presentation", "I learned a lot", "great improvements", "eye-opener", "hugely customizable" were very much appreciated.
But, the best reward for me was the excitement I saw in people's eyes when I was able to propose CB powered solutions and add-ons for their specific use case needs.
Most people (I am also guilty :-( ) usually just dive in and start playing with Community Builder. This is certainly the quickest approach but it is also not the most productive one.
During the NJ meeting I noticed that most of the attendees were not aware of the new CB PRIMER Book (you need to be logged in to download) and how it could help you understand and tap into the great solution providing potential of Community Builder. It is a great read and it will inspire you to learn and explore CB much more and easier than the heads-on approach.
Once people realize how powerful CB is they can continue the free discovery process by monitoring the open-to-all support forums and see even more CB powered solution proposals given to our paid supporters.
A big thank you to the New Jersey Joomla user group for organizing the presentation and giving me the opportunity to meet everyone.
JWC15 will be happening in Bangalore, India, on November 6-8. This year Joomla celebrates it’s 10th year, with three days of amazing keynotes, workshops, and sessions where you can learn, connect with Joomla experts, and help plan the next decade of Joomla.
Joomlapolis and CB Team members will not be able to make it but there will surely be many Community Builders present!
Check your Joomlapolis newsletter for a great 20% off coupon on all JWC tickets.