PT-2022-2575 · Twig+3 · Twig+3

Marlon Starkloff

·

Published

2022-02-04

·

Updated

2024-04-04

·

CVE-2022-23614

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Twig versions prior to the patched version
Description The issue arises from the lack of proper enforcement of the constraint that the arrow parameter of the sort filter must be a closure when in sandbox mode. This could lead to code injection of arbitrary PHP code, allowing attackers to run arbitrary PHP functions. The patched versions now disallow calling non-closure in the sort filter.
Recommendations For all affected versions of Twig, users are advised to upgrade to a patched version to resolve the issue. As a temporary workaround, consider disabling the sort filter until a patch is available. Restrict access to the arrow parameter of the sort filter to minimize the risk of exploitation. Avoid using the arrow parameter in the affected sort filter until the issue is resolved.

Exploit

Fix

Code Injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2023-6184
ALT-PU-2024-4537
ALT-PU-2024-4547
ALT-PU-2024-4961
BDU:2022-03019
CVE-2022-23614
DSA-5107-1
GHSA-5MV2-RX3Q-4W2V
USN-5947-1

Affected Products

Linuxmint
Red Os
Twig
Ubuntu