CVE Vulnerabilities

CVE-2025-24374

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Published: Jan 29, 2025 | Modified: Jan 29, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
LOW

Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0.

Weakness

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Affected Software

Name Vendor Start Version End Version
Php-twig Ubuntu upstream *

Potential Mitigations

References