Twig Field Value - Moderately critical - Access bypass - SA-CONTRIB-2022-058

Twig Field Value - Moderately critical - Access bypass - SA-CONTRIB-2022-058

Project: Twig Field Value
Date: 2022-October-12
Security risk: Moderately critical 12∕25 
Vulnerability: Access bypass

Description

This module enables themers to get partial data from field render arrays. It gives them more control over the output without drilling deep into the render array or using preprocess functions.

The module doesn't sufficiently apply access restrictions when using the filters field_label, field_value, field_raw and field_target_entity.

This vulnerability is mitigated by the fact that these filters must be used in combination with either unpublished content or access control modules.

Solution

Install the latest version:

Nick Onom's picture
Nick Onom
Marketing Project Manager
Enthusiastic about all kinds of Open Source applications, AI, bitcoins, but mostly Drupal and Backdrop. For last years has been actively developing AltaGrade's new back-end system.

We value your opinion. Please add your feedback.