DRUPAL-CONTRIB-2022-058
Dashboard / Vulnerabilities / DRUPAL-CONTRIB-2022-058
DRUPAL-CONTRIB-2022-058
Summary:
Details: This module enables themers to get partial data from field render arrays. It gives them more control over the output without drilling deep into the render array or using preprocess functions. The module doesn't sufficiently apply access restrictions when using the filters field\_label, field\_value, field\_raw and field\_target\_entity. This vulnerability is mitigated by the fact that these filters must be used in combination with either unpublished content or access control modules.
References: https://www.drupal.org/sa-contrib-2022-058
Affected packages
Package
Name: drupal/twig_field_value
Purl: pkg:composer/drupal/twig_field_value?repository_url=https:%2F%2Fpackages.drupal.org%2F8
Affected ranges
Type: ECOSYSTEM
Events:
