Security
JCH Optimize 9.4.1 fixes six high-severity Joomla flaws
JCH Optimize versions before 9.4.0 are affected by six high-rated security issues, including XSS and an unauthenticated page-cache endpoint; administrators should install 9.4.1.
mySites.guru published research into the Joomla extension from developer Samuel Marshall. The affected releases include both Free and Pro editions. No CVE identifiers have been assigned, and the report does not document exploitation.
The issues include cross-site scripting caused by unsafe URL decoding, an unauthenticated request that could invoke component models, missing CSRF and administrator-permission checks, unsafe image paths, an open redirect, and a parameter that disabled front-end optimization. The release also addresses medium-severity page-cache, host-header and file-path handling problems.
Version 9.4.0 contains the security fixes but introduced fatal errors for Pro installations using Redis or APCu. Version 9.4.1 fixes that regression and is the recommended update. The affected range is every release before 9.4.0; the older Joomla 3 line has no security fix.
Administrators should update the component and its relevant plugins to 9.4.1, verify that all report the same version, and use Filesystem storage temporarily if an immediate update is impossible. Joomla 3 sites should remove the old extension line or plan a migration.
Originally reported by mySites.guru.