{"id":"DRUPAL-CONTRIB-2022-058","details":"This module enables themers to get partial data from field render arrays. It gives them more control over the output without drilling deep into the render array or using preprocess functions.\n\nThe module doesn't sufficiently apply access restrictions when using the filters field\\_label, field\\_value, field\\_raw and field\\_target\\_entity.\n\nThis vulnerability is mitigated by the fact that these filters must be used in combination with either unpublished content or access control modules.","modified":"2026-09-10T03:46:06.029907785Z","published":"2022-10-12T19:41:07Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2022-058"}],"affected":[{"package":{"name":"drupal/twig_field_value","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/twig_field_value?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.1"}],"database_specific":{"constraint":"\u003c2.0.1"}}],"database_specific":{"affected_versions":"\u003c2.0.1","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/twig_field_value/DRUPAL-CONTRIB-2022-058.json"}}],"schema_version":"1.9.0","credits":[{"name":"Erik Stielstra","contact":["https://www.drupal.org/user/73854"]}]}