registration 7.x-2.0-beta4

Security update

This is a security release for the 7.x-1.x branch of the module. Information about the update can be found in the security announcement.

Changes since 7.x-1.7:

Revert "Issue #2357533 by alberto56: Improve registration_administer_registrations_access() function so one can check access for other accounts (not the current one)"

search_api 8.x-1.27

Security update
Bug fixes

This is release 8.x-1.27 of the Search API module for Drupal 9/10. It contains a bug fix for a security issue and should be installed as soon as possible.

Fixes Search API - Moderately critical - Information Disclosure - SA-CONTRIB-2022-059

Other changes included in this release:

twig_field_value 2.0.1

Security update

Resolves SA-CONTRIB-2022-058.

Drupal 10 compatibility

  • Issue #3290158 by Project Update Bot: Automated Drupal 10 compatibility fixes
  • Issue #3262909 by Sutharsan: Fix deprecated test code

Coding standards

  • Issue #3295680 by Sutharsan, Dharti Patel: Drupal Coding Standards
  • Issue #3295503 by Meeni_Dhobale, JatinGupta40: Drupal coding standards are not followed in README file.

drupal 9.4.7

Insecure
Security update

This is a security release of the Drupal 9 series.

This release fixes security vulnerabilities. Sites are urged to update immediately after reading the notes below and the security announcement:

No other fixes are included.

drupal 9.3.22

Security update
Insecure
Insecure

This is a security release of the Drupal 9 series.

This release fixes security vulnerabilities. Sites are urged to update immediately after reading the notes below and the security announcement:

No other fixes are included.

s3fs 7.x-2.14

Security update

This module enables you to utilize S3-compatible storage as a Drupal filesystem.

The module doesn't sufficiently prevent file access across multiple filesystem schemes stored in the same bucket.

This vulnerability is mitigated by the fact that an attacker must obtain a method to access arbitrary file paths, the site must have public or private takeover enabled, and the file metadata cache must be ignored.

Pages

Subscribe with RSS Subscribe to RSS - Security update