janrain_capture 6.x-1.1

Security update
Bug fixes
  • Resolved an open redirect issue DRUPAL-SA-CONTRIB-2012-098
  • Removed the theme template and replaced with raw output
  • Resolved access callbacks in hook_menu to appropriate access functions
  • Corrected xdcomm.js paths
  • Per-user, encrypt the refresh_token stored in the session data

janrain_capture 7.x-1.1

Security update
Bug fixes
  • Resolved an open redirect issue DRUPAL-SA-CONTRIB-2012-098
  • Removed the theme template and replaced with raw output
  • Resolved access callbacks in hook_menu to appropriate access functions
  • Corrected xdcomm.js paths
  • Per-user, encrypt the refresh_token stored in the session data
  • Removed jquery_update dependency
  • Changed admin settings menu path

nodehierarchy 6.x-1.5

Security update
Bug fixes

Fixed XSRF issue which potentially allowed malicious users to craft a link which could change the order of a node's children if accidentally visited by a site admin. See SA-CONTRIB-2012-099 - Node Hierarchy - Cross Site Request Forgery - CSRF

commons 6.x-2.7

Security update
Bug fixes
Insecure

Note, to get the fully packaged version of Drupal Commons, download Commons from Acquia.com as the Drupal.org release contains only the Commons feature modules and does not contain Drupal core or contributed projects.

For the latest release notes an upgrade instructions, see https://docs.acquia.com/commons/whats-new.

simplenews 7.x-1.0-rc1

Security update
Insecure

This is the first release candidate for Simplenews 7.x-1.x that includes a large number of bugfixes including a fix for a security issue, see SA-CONTRIB-2012-095 - Simplenews - Information Disclosure for details.

Changes since 7.x-1.0-beta2:

Pages

Subscribe with RSS Subscribe to RSS - Security update