Description
A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4419-1 | twig security update |
EUVD |
EUVD-2022-1558 | A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place. |
Github GHSA |
GHSA-vxrc-68xx-x48g | Twig Sandbox Information Disclosure |
Ubuntu USN |
USN-5947-1 | Twig vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T22:10:08.258Z
Reserved: 2019-03-23T00:00:00.000Z
Link: CVE-2019-9942
No data.
Status : Modified
Published: 2019-03-23T15:29:00.323
Modified: 2024-11-21T04:52:38.353
Link: CVE-2019-9942
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Github GHSA
Ubuntu USN