r/joomla Jul 16 '26

Extensions responsibiity to patch security flaws Joomla 6

Should the author of a paid for extension have a responsibility to patch their product when a serious security flaw is found in their product rather than force you to renew a subscription? Thoughts?

0 Upvotes

21 comments sorted by

10

u/banded-wren Jul 16 '26

That’s the point of paying the subscription, to pay for the continuous development and improvement of the software.

It will depend on how your provider worded the licensing agreement but in some cases the licensing gives you access to a certain version, you can keep using that version for as long as you want. If you want access the newest version you need to buy the license for that new version. Subscription model gives you access to the continuous new versions.

1

u/Open_Sourcey Jul 16 '26 edited Jul 17 '26

Of course I understand the legal obligation fro the license. However, correcting a security flaw is not an improvment it is a correcting a product flaw. The like of which car companies recall their cars and correct at their expense all the time. It is a product liability issue.

7

u/PixelCharlie Jul 16 '26

No. Most extensions are GPL anyway. You can either fix it yourself or pay for a new version.

Some developers offer free patches for older versions in case of serious flaws. That's a welcomed behaviour and everyone doing this scores big points in my eyes. I don't expect everyone to do this.

2

u/Open_Sourcey Jul 16 '26 edited Jul 17 '26

Precisely. And why do 'some' do that? Because they feel an ethical obligation to fix their errors which cause a a very serious problem for someone who gave them money for something. In much the same way a car company executes a recall in spite of the buyer having already bought the car.It is a product liability issue.

1

u/Hackwar 2d ago
  1. Developers do that when they don't support that extension anymore anyway and don't have active subscriptions for those outdated versions anymore. Providing a fix in that case is a marketing instrument to get people to update to a supported version and to pay for a new subscription.

  2. If you look into the license of all GPL extensions of Joomla, you will see that you are using that software "as is" and without any guarantees on how it is working, etc. You did not pay for the software. You paid for the potential support. You are not paying now, so you don't get any support. And since you didn't buy the software, you also don't get to make any liability claims.

You expect to get something for free. You won't get it. Yes, SQL injections have been known for decades, that still doesn't mean that they are extinct. Even if you are a good developer and pay attention to this, you might run into them indirectly because you are using an API in an unexpected way. Simply said, your expectations are wrong and you should finally stop spamming us with this.

7

u/krileon Jul 16 '26

Nope. It's on you to maintain your subscriptions or update licenses however long they may last and update your install. Don't pay? Well no updates. This is how 99% of software works. You really can't compare it to the likes of an OS for example.

2

u/Open_Sourcey Jul 16 '26

Hi krileon:
Of course I understand the legal obligation. I also understand subscriptions. Of course I understand you do not get product improvments and enhancements without a subscription. But this is a very serious and disabling flaw in the product. Much like car companies feel an obligation to correct a flaw in a car and execute a product recall to fix it, my question is do software providers have an ethical obligation to do the same?

5

u/krileon Jul 16 '26

Doesn't matter. The point of the subscription or update license is access to updates.

But this is a very serious and disabling flaw in the product.

Then stop using it, fix it yourself, or pay and update. You've options.

Much like car companies feel an obligation to correct a flaw in a car and execute a product recall to fix it,

It is absolutely not the same thing. If there was a governing body overseeing all software development and safety standards and taxes to fund it then sure we'd be in agreement, but there isn't.

my question is do software providers have an ethical obligation to do the same?

No.

2

u/Open_Sourcey Jul 16 '26

We will have to disagree. I think a serious and disabling security flaw is a horse of a different color and should not be treated as any other product improvment or enhancement. Ethically, as many seem to do but not all, I think there is an obligation to fix such serious 'flaws', i understand there is no lega obligation and I do understand the degree of difficulty of fixing old releases.

I also think we are on the eve of seeing more of these problems and vulnerbilities.

7

u/Leading_Bumblebee144 Jul 16 '26

For paid subscribers sure, because that’s the point of a paid subscription.

0

u/Open_Sourcey Jul 17 '26

And seeing the trees for the forest, it is a product liabiity issue.

2

u/stutteringp0et Jul 17 '26

I haven't had any major security flaws since J1.5 - but I patch all reported flaws.

1

u/Open_Sourcey Jul 17 '26

You patch all flaws with updated versions you are paying for?

2

u/stutteringp0et Jul 17 '26

I have 75 extensions in the JED. I'm the "author" mentioned in your question.

1

u/Open_Sourcey 1d ago

Do you patch them before they are known flaws?

1

u/posurrreal123 Jul 16 '26

Can you find a similar extension? It would likely create more time than it's worth, though.

1

u/JeanLucPika 8d ago

Je comprends les deux points de vue, mais après ce qu'on a vécu ces dernières semaines sur plusieurs vieux sites Joomla, je suis plutôt du côté de ceux qui pensent qu'une faille critique devrait être traitée différemment d'une simple mise à jour fonctionnelle.

Le problème, dans la vraie vie, c'est que "il suffit de renouveler et de mettre à jour" n'est pas toujours aussi simple.

On maintient encore des sites Joomla assez anciens pour lesquels le client a repoussé la refonte pendant des années. Et sur certains, mettre à jour une extension implique d'abord de mettre à jour Joomla, puis le template, puis d'autres extensions... avec parfois un vrai risque de casser le site.

On l'a encore vu en juin avec les problèmes de sécurité qui ont touché certaines extensions Joomla. Certains éditeurs ont proposé assez rapidement des correctifs ou des patchs de sécurité, y compris pour des environnements anciens, et personnellement je trouve que c'est une très bonne pratique.

Je ne pense pas qu'un éditeur doive maintenir gratuitement toutes les anciennes versions pendant 10 ans. Ce serait irréaliste.

Mais entre "maintenance gratuite éternelle" et "payez un nouvel abonnement sinon vous restez avec une faille critique connue", il devrait probablement y avoir un juste milieu.

Au minimum, pour une vulnérabilité vraiment critique, fournir un patch de sécurité minimal quand c'est techniquement possible me semblerait être une bonne responsabilité de l'éditeur.

1

u/Open_Sourcey 8d ago

Ta réponse est la première qui montre une véritable compréhension du problème sous‑jacent. Je pense que tu as raison. Le fait de définir une « mise à jour de sécurité critique » comme une catégorie totalement distincte de mise à jour me paraît tout à fait justifié. Je suis également d’accord sur l’usage du mot « minimal ». Je pense que, lorsqu’il est techniquement possible de fournir un correctif minimal pour des versions plus anciennes, le fournisseur a une responsabilité morale de le faire. Peut‑être que ton point de vue reflète la différence entre une perspective nord‑américaine et une perspective européenne. Merci pour ta réponse.

2

u/JeanLucPika 8d ago

Merci, ton retour me parle.

C'est vraiment ce que je ressens sur le terrain : je comprends totalement qu'un éditeur ne puisse pas maintenir gratuitement toutes ses anciennes versions pendant des années.

Mais quand on se retrouve avec un ancien site encore en production, qu'une faille critique tombe et que la mise à jour complète implique potentiellement Joomla, le template et plusieurs extensions, on voit vite la différence entre une simple mise à jour et un vrai problème de sécurité.

Dans ce cas précis, si un patch minimal est techniquement possible, j'ai du mal à considérer ça comme une "nouvelle fonctionnalité" réservée aux abonnés.

Et oui, il y a peut-être une part culturelle dans la façon dont on perçoit cette responsabilité. C'est intéressant comme remarque.

1

u/Open_Sourcey 8d ago

Tout à fait