Twig Sandbox Information Disclosure
Low severity
GitHub Reviewed
Published
Mar 26, 2022
to the GitHub Advisory Database
•
Updated Sep 21, 2023
Package
Affected versions
< 1.38.0
>= 2.0.0, < 2.7.0
Patched versions
1.38.0
2.7.0
Description
Published by the National Vulnerability Database
Mar 23, 2019
Published to the GitHub Advisory Database
Mar 26, 2022
Reviewed
Mar 26, 2022
Last updated
Sep 21, 2023
A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the
__toString()
method on an object even if not allowed by the security policy in place.References