twig_field_valueThis module enables themers to get partial data from field render arrays. It gives them more control over the output without drilling deep into the render array or using preprocess functions.
The module doesn't sufficiently apply access restrictions when using the filters field_label, field_value, field_raw and field_target_entity.
This vulnerability is mitigated by the fact that these filters must be used in combination with either unpublished content or access control modules.
Install the latest version:
- If you use the Twig Field Value module version 8.x-1.x or 2.0.x, upgrade to Twig Field Value 2.0.1
- Damien McKenna of the Drupal Security Team
- Greg Knaddison of the Drupal Security Team
- Ivo Van Geertruyen of the Drupal Security Team