Maintenance and security release of the Drupal 7 series.
This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the notes below and the security announcement:
No other fixes are included.
Security update. SA-CONTRIB-2014-098 - CKEditor - Cross Site Scripting (XSS)
Security update.
SA-CONTRIB-2014-098 - CKEditor - Cross Site Scripting (XSS)
Password protection bypass issue is fixed.
SA-CONTRIB-2014-111 - Protected Pages - Password Protection Bypass
Fixes: SA-CONTRIB-2014-097 - nodeaccess - Access Bypass - Add weight to alias for disabled role. - Issue #436918: Aliases not being saved for disabled role. - Issue #557344: Invalid argument in nodeaccess_delete_userreference.