This is a security release of the Drupal 9 series.
This release fixes security vulnerabilities. Sites are urged to update immediately after reading the notes below and the security announcements:
No other fixes are included.
This release contains only the fix to SA-CONTRIB-2022-022.
Changes since 7.x-2.2:
This release fixes security vulnerabilities. Sites are urged to update immediately after reading the notes below and the security announcement:
Embed - Moderately critical - Cross Site Scripting - SA-CONTRIB-2022-042
recrit, Shashwat Purav, mstrelan
Issues: 3 issues resolved.
Changes since 8.x-1.4:
Apigee Edge - Moderately critical - Access bypass - SA-CONTRIB-2022-045
Github milestone: 8.x-1.26
Changelog:
Update Cache-Control parameters to no-store, via PR #709.