A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Twig | Symfony | * | 1.38.0 (excluding) |
Twig | Symfony | 2.0.0 (including) | 2.7.0 (excluding) |
Php-twig | Ubuntu | upstream | * |
Twig | Ubuntu | bionic | * |
Twig | Ubuntu | cosmic | * |
Twig | Ubuntu | esm-apps/bionic | * |
Twig | Ubuntu | esm-apps/xenial | * |
Twig | Ubuntu | upstream | * |
Twig | Ubuntu | xenial | * |