Drupals David Rothstein has announced the availability of Drupal 7.27 and Drupal 6.31. The latest versions fix a moderately critical information disclosure vulnerability.
A CVE identifier is being requested for the security hole. In the meantime, Drupal refers to it as SA-CORE-2014-002.
When pages are cached for anonymous users, form state may leak between anonymous users. As a consequence there is a chance that interim form input recorded for one anonymous user (which ma…