CVE Vulnerabilities

CVE-2024-45411

Protection Mechanism Failure

Published: Sep 09, 2024 | Modified: Nov 21, 2024
CVSS 3.x
8.6
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0.

Weakness

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Affected Software

Name Vendor Start Version End Version
Twig Symfony 1.0.0 (including) 1.44.8 (excluding)
Twig Symfony 2.0.0 (including) 2.16.1 (excluding)
Twig Symfony 3.0.0 (including) 3.14.0 (excluding)

References