CVE Vulnerabilities

CVE-2024-45411

Protection Mechanism Failure

Published: Sep 09, 2024 | Modified: Nov 21, 2024
CVSS 3.x
8.6
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0.

Weakness

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Affected Software

NameVendorStart VersionEnd Version
TwigSymfony1.0.0 (including)1.44.8 (excluding)
TwigSymfony2.0.0 (including)2.16.1 (excluding)
TwigSymfony3.0.0 (including)3.14.0 (excluding)
Php-twigUbuntuesm-apps/jammy*
Php-twigUbuntuesm-apps/noble*
Php-twigUbuntufocal*
Php-twigUbuntujammy*
Php-twigUbuntunoble*
Php-twigUbuntuoracular*
Php-twigUbuntuupstream*

References