Описание
Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig autoescaping to emit attacker-controlled markup unescaped when spaceless is applied to untrusted input. This issue is fixed in version 3.26.0.
Ссылки
- Patch
- Release Notes
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.26.0 (исключая)
cpe:2.3:a:symfony:twig:*:*:*:*:*:*:*:*
EPSS
Процентиль: 7%
0.00169
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-116
Связанные уязвимости
CVSS3: 5.4
ubuntu
28 дней назад
Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig autoescaping to emit attacker-controlled markup unescaped when spaceless is applied to untrusted input. This issue is fixed in version 3.26.0.
CVSS3: 5.4
debian
28 дней назад
Twig is a template language for PHP. Prior to 3.26.0, the deprecated s ...
github
3 месяца назад
Twig: The `spaceless` filter implicitly marks its output as safe
EPSS
Процентиль: 7%
0.00169
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-116