Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-24374

Опубликовано: 29 янв. 2025
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS3: 4.3

Описание

Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0.

РелизСтатусПримечание
devel

not-affected

esm-apps/focal

not-affected

code not present
esm-apps/jammy

not-affected

code not present
esm-apps/noble

not-affected

code not present
focal

not-affected

code not present
jammy

not-affected

code not present
noble

not-affected

code not present
oracular

not-affected

code not present
plucky

not-affected

questing

not-affected

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

needs-triage

esm-apps/xenial

needs-triage

esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

questing

DNE

Показывать по

EPSS

Процентиль: 34%
0.00141
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
около 1 года назад

Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0.

CVSS3: 4.3
debian
около 1 года назад

Twig is a template language for PHP. When using the ?? operator, outpu ...

CVSS3: 4.3
github
около 1 года назад

Twig security issue where escaping was missing when using null coalesce operator

EPSS

Процентиль: 34%
0.00141
Низкий

4.3 Medium

CVSS3