Still on Drupal 7? Security support for Drupal 7 ended on 5 January 2025. Please visit our Drupal 7 End of Life resources page to review all of your options.
A serious security issue is fixed in this small release. Until now it was possible to bypass the argument validation in the card listing view. The exception value was left as the default setting, which is hidden in a collapsed fieldset in Views' contextual filter configuration. Users could simply list all cards visiting the URI, user/all/cards. Last four digits, names on the cards and expiration dates were exposed.