See SA-CONTRIB-2015-130
me aliases - Moderately Critical - Open Redirect - SA-CONTRIB-2015-128
This release fixes a Cross-Site Scripting vulnerability (see Shibboleth authentication - Moderately critical - Cross Site Scripting (XSS) - SA-CONTRIB-2015-129)
This release is an update to 6.x-4.2-rc1, which is a bugfix and a feature release.
This release is an update to 7.x-4.2-rc1, which is a bugfix and a feature release.
Changes since 7.x-2.12: