Vulnerability from drupal
Published
2023-08-30 16:22
Modified
2023-08-30 18:51
Summary
Details
This module makes PatternLab's custom Twig functions available to Drupal theming.
The module's included examples don't sufficiently filter data.
This vulnerability is mitigated by the fact that the included examples must have been copied to a site's theme.
Credits
Pierre Rudloff
www.drupal.org/user/3611858
{
"affected": [
{
"database_specific": {
"affected_versions": "\u003c1.1.1"
},
"package": {
"ecosystem": "Packagist:https://packages.drupal.org/8",
"name": "drupal/unified_twig_ext"
},
"ranges": [
{
"database_specific": {
"constraint": "\u003c1.1.1"
},
"events": [
{
"introduced": "0"
},
{
"fixed": "1.1.1"
}
],
"type": "ECOSYSTEM"
}
],
"severity": []
}
],
"aliases": [],
"credits": [
{
"contact": [
"https://www.drupal.org/user/3611858"
],
"name": "Pierre Rudloff"
}
],
"details": "This module makes PatternLab\u0027s custom Twig functions available to Drupal theming.\n\nThe module\u0027s included examples don\u0027t sufficiently filter data.\n\nThis vulnerability is mitigated by the fact that the included examples must have been copied to a site\u0027s theme.",
"id": "DRUPAL-CONTRIB-2023-041",
"modified": "2023-08-30T18:51:23.000Z",
"published": "2023-08-30T16:22:06.000Z",
"references": [
{
"type": "WEB",
"url": "https://www.drupal.org/sa-contrib-2023-041"
}
],
"schema_version": "1.7.0"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…