CVE-2024-51754
CVSS V2 None
CVSS V3 None
Description
Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not allowed by the security policy when the object is part of an array or an argument list (arguments to a function or a filter for instance). This issue has been patched in versions 3.11.2 and 3.14.1. All users are advised to upgrade. There are no known workarounds for this issue.
Overview
- CVE ID
- CVE-2024-51754
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-11-06T19:28:17.553Z
- Last Modified Date
- 2024-11-06T19:44:28.082Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/twigphp/Twig/security/advisories/GHSA-6377-hfv9-hqf6 | x_refsource_CONFIRM |
https://github.com/twigphp/Twig/commit/2bb8c2460a2c519c498df9b643d5277117155a73 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-51754 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-51754 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-11-07 13:06:24 | Added to TrackCVE |