Protection Mechanism Failure in Twig - CVE-2024-45411
Published: December 30, 2024
Vulnerability identifier: #VU102072
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-45411
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to sandbox security checks are not run under some circumstances. An attacker can bypass the sandbox restrictions.
Affected software
Twig
Debian Linux
Ubuntu
php-twig (Debian package)
php-twig (Ubuntu package)
IBM API Connect
Debian Linux
Ubuntu
php-twig (Debian package)
php-twig (Ubuntu package)
IBM API Connect
How to mitigate CVE-2024-45411
Install updates from vendor's website.
Twig - addressed in versions 1.44.8, 2.16.1, 3.14.0
php-twig (Debian package) - update to 3.5.1-1+deb12u1
php-twig (Ubuntu package) - addressed in versions 3.8.0-2ubuntu1, 3.8.0-3ubuntu1
IBM API Connect - update to 10.0.9.0
php-twig (Debian package) - update to 3.5.1-1+deb12u1
php-twig (Ubuntu package) - addressed in versions 3.8.0-2ubuntu1, 3.8.0-3ubuntu1
IBM API Connect - update to 10.0.9.0
External References
- https://github.com/twigphp/Twig/security/advisories/GHSA-6j75-5wfj-gh66
- https://github.com/twigphp/Twig/commit/11f68e2aeb526bfaf638e30d4420d8a710f3f7c6
- https://github.com/twigphp/Twig/commit/2102dd135986db79192d26fb5f5817a566e0a7de
- https://github.com/twigphp/Twig/commit/7afa198603de49d147e90d18062e7b9addcf5233