Formatter Field
An ordinary account on the site could write malicious data directly into a display settings field. This could allow them to view or alter any information on the site including the underlying code.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if a person has access rights to edit a piece of content with a display settings field and the site allows full edit access through a data feed or another direct method.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Formatter Field to 2.0.0.
For developers: what the fix changed
The fix updates calls to `unserialize()` in `DefaultFormatter.php`, `FromFieldFormatter.php`, and `FormatterWidget.php` to include `['allowed_classes' => FALSE]`, preventing object injection. It also changes `#markup` to `#plain_text` when rendering settings in `DefaultFormatter.php`.
Also in this release Added compatibility for Drupal 9, 10, and 11, introduced GitLab CI configuration, fixed coding standards, and modernised the README file.
.cspell-project-words.txt+5 −0.gitlab-ci.yml+104 −0README.md+44 −0config/schema/formatter_field.schema.yml+2 −2formatter_field.info.yml+1 −1formatter_field.module+1 −1readme.txt+0 −24src/Plugin/Field/FieldFormatter/DefaultFormatter.php+5 −5 fixsrc/Plugin/Field/FieldFormatter/FromFieldFormatter.php+3 −3 fixsrc/Plugin/Field/FieldType/FormatterItem.php+9 −6src/Plugin/Field/FieldWidget/FormatterWidget.php+8 −7 fix