Описание
A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place.
Ссылки
- PatchThird Party Advisory
- Mailing ListThird Party Advisory
- PatchVendor Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Mailing ListThird Party Advisory
- PatchVendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Одно из
EPSS
3.7 Low
CVSS3
4.3 Medium
CVSS2
Дефекты
Связанные уязвимости
A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place.
A sandbox information disclosure exists in Twig before 1.38.0 and 2.x ...
Уязвимость компилирующего обработчика шаблонов Twig, связанная с ошибками функционирования изолированной программной среды, позволяющая нарушителю получить доступ к конфиденциальным данным
EPSS
3.7 Low
CVSS3
4.3 Medium
CVSS2