--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2020-fbb94073a1
2020-09-13 14:17:24.303433
--------------------------------------------------------------------------------

Name        : drupal7
Product     : Fedora 31
Version     : 7.72
Release     : 1.fc31
URL         : https://www.drupal.org
Summary     : An open-source content-management platform
Description :
Equipped with a powerful blend of features, Drupal is a Content Management
System written in PHP that can support a variety of websites ranging from
personal weblogs to large community-driven websites.  Drupal is highly
configurable, skinnable, and secure.

--------------------------------------------------------------------------------
Update Information:

- https://www.drupal.org/project/drupal/releases/7.72     - [Drupal core -
Critical - Cross Site Request Forgery - SA-
CORE-2020-004](https://www.drupal.org/sa-core-2020-004) / CVE-2020-13663 -
https://www.drupal.org/project/drupal/releases/7.71 -
https://www.drupal.org/project/drupal/releases/7.70     - [Drupal core -
Moderately critical - Cross Site Scripting - SA-
CORE-2020-002](https://www.drupal.org/sa-core-2020-002) / CVE-2020-11022 /
CVE-2020-11023     - [Drupal core - Moderately critical - Open Redirect - SA-
CORE-2020-003](https://www.drupal.org/sa-core-2020-003) / CVE-2020-13662
--------------------------------------------------------------------------------
ChangeLog:

* Fri Sep  4 2020 Shawn Iwinski  - 7.72-1
- Update to 7.72
- SA-CORE-2020-004/CVE-2020-13663 (RHBZ #1860912, #1860913)
* Mon Jul 27 2020 Fedora Release Engineering  - 7.70-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
* Sun May 31 2020 Shawn Iwinski  - 7.70-2
- rpmbuild sub-pkg: Fix auto-provides for F32+
* Fri May 22 2020 Peter Borsa  - 7.70-1
- Update to 7.70
- RHBZ #1837516 / SA-CORE-2020-003
- RHBZ #1828416 / SA-CORE-2020-002
* Fri May 22 2020 Peter Borsa  - 7.69-3
- Remove php-recode as dependency
* Tue Jan 28 2020 Fedora Release Engineering  - 7.69-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1828417 - CVE-2020-11022 drupal7: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=1828417
  [ 2 ] Bug #1850013 - CVE-2020-11023 drupal7: jQuery: passing HTML containing