SB2024123097 - Protection Mechanism Failure in twigphp Twig
Published: December 30, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Protection Mechanism Failure (CVE-ID: CVE-2024-45411)
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to sandbox security checks are not run under some circumstances. An attacker can bypass the sandbox restrictions.
Remediation
Install update from vendor's website.
References
- https://github.com/twigphp/Twig/security/advisories/GHSA-6j75-5wfj-gh66
- https://github.com/twigphp/Twig/commit/11f68e2aeb526bfaf638e30d4420d8a710f3f7c6
- https://github.com/twigphp/Twig/commit/2102dd135986db79192d26fb5f5817a566e0a7de
- https://github.com/twigphp/Twig/commit/7afa198603de49d147e90d18062e7b9addcf5233