dvg 7.x-1.9

Security update

This security release contains 2 security updates for contrib modules (Link & Context) and contains a security fix for the dvg_domains module.
You should update ASAP or apply the related patches to remain safe.

Changes since 7.x-1.8:

eu_cookie_compliance 8.x-1.3

Security update
Bug fixes
Insecure

Fixed a security issue where some output was not sanitized, causing potential XSS. The issue is mitigated by the attacker needing to have the permission "Administer EU Cookie Compliance", and in addition access to a text format that doesn't sanitize output. Also several bug fixes.

EU Cookie Compliance - Critical - Cross site scripting - SA-CONTRIB-2019-033

Fix security issue involving XSS. Mitigated by need to have admin access
Issue #3002528 by svenryen: Withdraw consent after agreeing is not working correctly
Issue #3008618 by svenryen: attachBehaviors after loading blacklisted scripts
Issue #2999117 by Dakwamine: In opt-out mode, do not ask again the user if he wants to consent after a withdraw
Issue #2973700 by AdamPS, svenryen: Consent by clicking option to exclude pages
Issue #2985662 by COBadger, svenryen: Missing button
Issue #3013518 by tauno: Use CloudFlare's CF-IPCountry as a fallback if available
Issue #3012020 by Leo Pitt: Spaces between class attributes and "="
Issue #2985558 by EduardoMadrid, svenryen: Convert javascript uris like public://path/file.js to relative paths
Issue #2994592 by jcnventura, svenryen, artfulrobot: Deletes cookies every 5s
Issue #3001177 by deepanker_bhalla, denisveg: Coding standard
Issue #2985543 by leymannx: Notice: Undefined variable: primary_button_label
Issue #2986882 by svenryen, smokris: Key to json hash cannot be "class" as it is a reserved word, use of "let" is not supported by all browsers as is ECMAScript

eu_cookie_compliance 7.x-1.26

Security update
Bug fixes

Fixed a security issue where some output was not sanitized, causing potential XSS. The issue is mitigated by the attacker needing to have the permission "Administer EU Cookie Compliance". Also several bug fixes. See EU Cookie Compliance - Critical - Cross site scripting - SA-CONTRIB-2019-033.

Fix security issue involving XSS. Mitigated by need to have admin access
Issue #3002528 by svenryen: Withdraw consent after agreeing is not working correctly
Issue #3020156 by svenryen: drupalSettings wrongly used in withdrawAction function
Issue #3008618 by svenryen: attachBehaviors after loading blacklisted scripts
Issue #2999117 by Dakwamine: In opt-out mode, do not ask again the user if he wants to consent after a withdraw
Issue #2973700 by AdamPS, svenryen: Consent by clicking option to exclude pages
Issue #3007865 by qwertyllo, das-peter, mfernea: Javascript undefined error after file uploads / ajax calls
Issue #2985662 by COBadger, svenryen: Missing button
Issue #3013518 by tauno, svenryen: Use CloudFlare's CF-IPCountry as a fallback if available
Issue #3013166 by das-peter: rror: Using $this when not in object context in eu_cookie_compliance_admin_form()
Issue #3012020 by Leo Pitt, svenryen: Spaces between class attributes and "="
Issue #2985558 by EduardoMadrid, svenryen: Convert javascript uris like public://path/file.js to relative paths
Issue #2994592 by jcnventura, svenryen, artfulrobot: Deletes cookies every 5s
Issue #2985520 by jasa, jyraya: After updating the module, a warning message appears about undefined withdraw_message, consent_storage_method and disabled_javascripts indexes
Issue #3001177 by svenryen, deepanker_bhalla, denisveg: Coding standard
Issue #2985543 by leymannx, svenryen: Notice: Undefined variable: primary_button_label
Issue #2986882 by smokris: Key to json hash cannot be "class" as it is a reserved word, use of "let" is not supported by all browsers as is ECMAScript

ubercart 7.x-3.12

Security update
Insecure

Security release to fix Ubercart - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2019-03

This release also contains the patch from issue Support PHP 7.2, now that core Drupal does. That patch has been part of Ubercart 7.x-3.x-dev since July 2018, but this is the first fixed-point release to contain the patch since Drupal core became compatible with PHP 7.2 in November 2018.

Pages

Subscribe with RSS Subscribe to RSS - Security update