Security Issue in CMF

Events happening in the community are now at Drupal community events on www.drupal.org.
irakli's picture

There's a mild security issue in the latest recommended version of the CMF module (version included in OP 1.7): http://drupal.org/node/704114 which allows unregistered users to see unpublished content.

The issue is fixed in the Dev release of the module, which can be downloaded from: http://ftp.drupal.org/files/projects/cmf-6.x-2.x-dev.tar.gz

An immediate update is recommended.

Comments

Thanks for posting. There are

stattler's picture

Thanks for posting. There are few other modules for which updates are available. Could you please tell us which ones should we NOT update? Thanks again.

  1. Custom Page
  2. Features (I know that we should not update this)
  3. Nodewords (causes a lot of problem after update. I guess that is not an OP issue)
  4. Strongarm
  5. Devel
  6. Rubik
  7. Tao

Heh, I've been meaning to

irakli's picture

Heh, I've been meaning to post that list for a while, but could not get around.

Generally, the deal is: we try to thoroughly test everything as a whole, in OP, so if you update any module - it's at your own risk and on the conscience of the maintainer of the module (if they introduce new bugs :)).

However, some modules outright should not be updated, because they are patched and you would lose an important patch (unless you can re-apply one, which can be tricky). So, here's that list:

http://groups.drupal.org/node/60313

.............................................
http://twitter.com/inadarei

OpenPublish

Group organizers

Group categories

Group notifications

This group offers an RSS feed. Or subscribe to these personalized, sitewide feeds: