CVE-2024-45411
CVSS V2 None
CVSS V3 None
Description
Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0.
Overview
- CVE ID
- CVE-2024-45411
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-09-09T18:20:28.363Z
- Last Modified Date
- 2024-09-09T18:39:52.204Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/twigphp/Twig/security/advisories/GHSA-6j75-5wfj-gh66 | x_refsource_CONFIRM |
https://github.com/twigphp/Twig/commit/11f68e2aeb526bfaf638e30d4420d8a710f3f7c6 | x_refsource_MISC |
https://github.com/twigphp/Twig/commit/2102dd135986db79192d26fb5f5817a566e0a7de | x_refsource_MISC |
https://github.com/twigphp/Twig/commit/7afa198603de49d147e90d18062e7b9addcf5233 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-45411 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45411 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-09-10 13:08:04 | Added to TrackCVE |