ECA: Event - Condition - Action
The module does not properly clean template code when displaying it. An ordinary account on the site could use this to read some restricted data. They could not change any data.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youThis applies if the site runs an automation model that uses the template rendering action on a data flow.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this less critical. Fix it with the next routine update.
Tell your developerUpdate ECA: Event - Condition - Action to 2.1.20, 3.0.12 or 3.1.4, whichever branch you are on.
For developers: what the fix changed
The fix removes token replacement from the Twig template source in `Drupal\eca_render\Plugin\Action\Twig::doBuild` and its configuration form. This prevents token values from being evaluated as Twig code, closing the server side template injection vulnerability.
Also in this release Refactored a while loop in GetFieldValue and fixed a PHPStan issue in TokenDecoratorTrait.
modules/content/src/Plugin/Action/GetFieldValue.php+5 −1modules/render/src/Plugin/Action/Twig.php+2 −3 fixsrc/Token/TokenDecoratorTrait.php+1 −3