Fixes Modal Form - Critical - Access bypass - SA-CONTRIB-2020-029.
Group - Critical - Information Disclosure - SA-CONTRIB-2020-030
By removing node grants in 8.x-1.0, we made some regular access checks (not query access) too permissive but only if Group was the only module implementing hook_node_grants().
Renderkit - Less critical - Access bypass - SA-CONTRIB-2020-026.
Example security release, see #3154932: Creating an example security release
Example security release. See #3154932: Creating an example security release
Maintenance and security release of the Drupal 7 series.
This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the notes below and the security announcement:
No other fixes are included.