GHSA-vxrc-68xx-x48g
Dashboard / Vulnerabilities / GHSA-vxrc-68xx-x48g
Summary: Twig Sandbox Information Disclosure
Details: A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the `__toString()` method on an object even if not allowed by the security policy in place.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-9942, https://github.com/twigphp/Twig/commit/eac5422956e1dcca89a3669a03a3ff32f0502077, https://github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2019-9942.yaml, https://github.com/twigphp/Twig, https://seclists.org/bugtraq/2019/Mar/60, https://symfony.com/blog/twig-sandbox-information-disclosure, https://www.debian.org/security/2019/dsa-4419
Affected packages
Package
Name: twig/twig
Purl: pkg:composer/twig/twig
Affected ranges
Type: ECOSYSTEM
Events:
