Here's the security advisory:

https://www.drupal.org/SA-CORE-2014-005

We'll do a release ASAP after this is fixed!

Comments

  • dsnopek committed 47b7da9 on 7.x-1.x
    Issue #2357247 by dsnopek: Update to Drupal 7.32 for SA-CORE-2014-005.
    
dsnopek’s picture

Status: Active » Fixed

Committed! Starting on release now..

greggmarshall’s picture

Rather than open a new issue for this question, I'll ask it here for Google searchers.

We have inherited some sites that use Panopoly that apparently mis-use Panels/Views so updates have been problematic.

Given the seriousness of the exploit fixed in 7.32, can core be updated independently? I don't see any core patches in the .make files in the profile.

Thanks for your distribution and help.

dsnopek’s picture

Yeah, you can update core independently or use the patch which will work on any Drupal 7 version.

greggmarshall’s picture

Perfect, thanks for the quick reply

StuddMan’s picture

dsnopek do you have an ETA on when you guys can get 7.x-1.13 on Pantheon?

dsnopek’s picture

Ack, sorry, I simply forgot to push the changes to the Pantheon repo! It's pushed now.

FYI, this issue pertains to Panopoly 1.12 - the issue that would be more apropos to 1.13 is #2357515: panopoly_update_7102() breaks if block module is already enabled

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.