PT-2024-34886 · Twig+1 · Twig+1

Maantje

·

Published

2024-11-06

·

Updated

2024-11-08

·

CVE-2024-51755

CVSS v3.1

2.2

Low

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Twig versions prior to 3.11.2 Twig versions prior to 3.14.1
Description In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. They are now checked via the property policy and the isset() method is now called after the security check. This is a BC break.
Recommendations For versions prior to 3.11.2, upgrade to version 3.11.2 or later. For versions prior to 3.14.1, upgrade to version 3.14.1 or later. As a temporary workaround, consider restricting access to array-like objects in the sandbox mode until a patch is applied.

Exploit

Fix

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2024-51755
GHSA-JJXQ-FF2G-95VH

Affected Products

Debian
Twig