Displays your Terms & Conditions to users who want to register, and requires that they accept the T&C before their registration is accepted.
The security team is marking this module unsupported. There is a known security issue with the module that has not been fixed by the maintainer. If you would like to maintain this module, please read: https://www.drupal.org/node/251466
Versions affected
All versions
Drupal core is not affected. If you do not use the contributed Legal module, there is nothing you need to do.
Solution
If you use the Legal module for Drupal you should uninstall it.
This module alters the book module permissions model by letting you specify access/modify/delete rights on a per-book basis. Normally, book-related permissions provided by drupal core apply across all books, but this module will let you drill down as granular as to letting specific users have specific rights for specific books.
The security team is marking this module unsupported. There is a known security issue with the module that has not been fixed by the maintainer. If you would like to maintain this module, please read: https://www.drupal.org/node/251466
Versions affected
All versions
Drupal core is not affected. If you do not use the contributed Book access module, there is nothing you need to do.
Solution
If you use the Book access module for Drupal you should uninstall it.
Red Hat Security Advisory 2017-0933-01 – The kernel packages contain the Linux kernel, the core of any Linux operating system. These updated kernel packages include several security issues and numerous bug fixes. Space precludes documenting all of these bug fixes in this advisory.
An unauthenticated XSS vulnerability with FortiMail 5.0.0 – 5.2.9 and 5.3.0 – 5.3.8 could allow an attacker to execute arbitrary scripts in the security context of the browser of a victim logged in FortiMail, assuming the victim is social engineered into clicking an URL crafted by the attacker.
SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by parameter to calendar_functions.php or widget_Theme_functions.php, related to front_end/frontend_functions.php.