views_refresh 7.x-1.2

Security update

- Fixes Views refresh - Moderately Critical - Access Bypass - DRUPAL-SA-CONTRIB-2017-069
- Issue #2564205: Decode html entities for views_ajax calls: Decode entities for view arguments
- It's possible to alter view refresh command output
- Views settings are checked before processing

relation 7.x-1.1

Security update

Fixes: Relation - Moderately Critical - Access Bypass - DRUPAL-SA-CONTRIB-2017-063

If it is intended that relation endpoints (from relation dummy field widget display) should be shown to certain role, view relations permission should be given to those roles.

Pages

Subscribe with RSS Subscribe to RSS - Security update