https://www.drupal.org/sa-contrib-2024-061

Along with other protections, this release adds the 'allowed_classes' => FALSE option to unserialize() when importing content using the relevant format.

See: https://www.php.net/manual/en/function.unserialize.php

If for any reason you need that protection to be removed, you can set a variable - for example in settings.php:


$conf['node_export_allow_unsafe_unserialize'] = TRUE;

VCS Label
7.x-3.3
Core compatibility
Release type
Short description
Drupal 7 release
Packaged Git sha1
d1acbd4ef01834e30fb87054908a73b9b502dbd5
Release files
9fe62333cc0f1bf696bf5f7ea3611fab
Release file SHA-1 hash
c20002d0e671977b3c50e0cc90342f792100f2b1
Release file SHA-256 hash
183089aa080284fad67697e018de332ad72182b5e4528ddb3b8bc96943935d38
b15be62f074e67b0fc7a28641eee56a3
Release file SHA-1 hash
e968a0fcf4c189df382dd86ad4b311a6360eaea9
Release file SHA-256 hash
6977013e63c506c2a18176a84638d4079e1cc4f91e61dd18a5de078f579e9057