Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0.
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Twig | Symfony | 1.0.0 (including) | 1.44.8 (excluding) |
Twig | Symfony | 2.0.0 (including) | 2.16.1 (excluding) |
Twig | Symfony | 3.0.0 (including) | 3.14.0 (excluding) |