Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0.
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Twig | Symfony | 1.0.0 (including) | 1.44.8 (excluding) |
Twig | Symfony | 2.0.0 (including) | 2.16.1 (excluding) |
Twig | Symfony | 3.0.0 (including) | 3.14.0 (excluding) |
Php-twig | Ubuntu | esm-apps/jammy | * |
Php-twig | Ubuntu | esm-apps/noble | * |
Php-twig | Ubuntu | jammy | * |
Php-twig | Ubuntu | noble | * |
Php-twig | Ubuntu | oracular | * |
Php-twig | Ubuntu | upstream | * |