PT-2022-38366 · Packagist · Drupal/Twig Field Value

Published

2022-10-12

·

Updated

2022-10-12

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
This module enables themers to get partial data from field render arrays. It gives them more control over the output without drilling deep into the render array or using preprocess functions.
The module doesn't sufficiently apply access restrictions when using the filters field label, field value, field raw and field target entity.
This vulnerability is mitigated by the fact that these filters must be used in combination with either unpublished content or access control modules.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

DRUPAL-CONTRIB-2022-058

Affected Products

Drupal/Twig Field Value