Commerce invoices - Highly Critical - SQL Injection and Cross Site scripting - DRUPAL-SA-CONTRIB-2017-070
H5P - Critical - Reflected Cross Site Scripting (XSS) - DRUPAL-SA-CONTRIB-2017-071
Added possibility to restrict libraries Fixed bug with wrong path to export file Do not aggregate external assets Support strict SQL mode
Views 3.17 and Entity Reference 1.5 were released yesterday to fix moderately critical and security vulnerabilities. You can learn more in the security advisories:
Views - Moderately Critical - Access Bypass - DRUPAL-SA-CONTRIB-2017-068
Entity Reference - Moderately Critical - Access Bypass - DRUPAL-SA-CONTRIB-2017-067
Besides that, there's only a minor bug fix to WYSIWYG.
See the full changes below!
Changes since 8.x-2.0-alpha6:
Maintenance and security release of the Drupal 8 series.
This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the notes below and the security announcements:
No other fixes are included.