Логотип exploitDog
bind: "CVE-2022-23614"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2022-23614"

Количество 7

Количество 7

ubuntu логотип

CVE-2022-23614

больше 3 лет назад

Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions this constraint was not properly enforced and could lead to code injection of arbitrary PHP code. Patched versions now disallow calling non Closure in the `sort` filter as is the case for some other filters. Users are advised to upgrade.

CVSS3: 8.8
EPSS: Средний
redhat логотип

CVE-2022-23614

больше 3 лет назад

Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions this constraint was not properly enforced and could lead to code injection of arbitrary PHP code. Patched versions now disallow calling non Closure in the `sort` filter as is the case for some other filters. Users are advised to upgrade.

CVSS3: 8.8
EPSS: Средний
nvd логотип

CVE-2022-23614

больше 3 лет назад

Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions this constraint was not properly enforced and could lead to code injection of arbitrary PHP code. Patched versions now disallow calling non Closure in the `sort` filter as is the case for some other filters. Users are advised to upgrade.

CVSS3: 8.8
EPSS: Средний
debian логотип

CVE-2022-23614

больше 3 лет назад

Twig is an open source template language for PHP. When in a sandbox mo ...

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-5mv2-rx3q-4w2v

больше 3 лет назад

Code injection in Twig

CVSS3: 8.8
EPSS: Средний
fstec логотип

BDU:2022-03019

больше 3 лет назад

Уязвимость компилирующего обработчика шаблонов Twig, существующая из-за непринятия мер по нейтрализации специальных элементов, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 9.8
EPSS: Средний
redos логотип

ROS-20221222-05

больше 2 лет назад

Уязвимость php-twig3

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-23614

Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions this constraint was not properly enforced and could lead to code injection of arbitrary PHP code. Patched versions now disallow calling non Closure in the `sort` filter as is the case for some other filters. Users are advised to upgrade.

CVSS3: 8.8
50%
Средний
больше 3 лет назад
redhat логотип
CVE-2022-23614

Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions this constraint was not properly enforced and could lead to code injection of arbitrary PHP code. Patched versions now disallow calling non Closure in the `sort` filter as is the case for some other filters. Users are advised to upgrade.

CVSS3: 8.8
50%
Средний
больше 3 лет назад
nvd логотип
CVE-2022-23614

Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions this constraint was not properly enforced and could lead to code injection of arbitrary PHP code. Patched versions now disallow calling non Closure in the `sort` filter as is the case for some other filters. Users are advised to upgrade.

CVSS3: 8.8
50%
Средний
больше 3 лет назад
debian логотип
CVE-2022-23614

Twig is an open source template language for PHP. When in a sandbox mo ...

CVSS3: 8.8
50%
Средний
больше 3 лет назад
github логотип
GHSA-5mv2-rx3q-4w2v

Code injection in Twig

CVSS3: 8.8
50%
Средний
больше 3 лет назад
fstec логотип
BDU:2022-03019

Уязвимость компилирующего обработчика шаблонов Twig, существующая из-за непринятия мер по нейтрализации специальных элементов, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 9.8
50%
Средний
больше 3 лет назад
redos логотип
ROS-20221222-05

Уязвимость php-twig3

CVSS3: 9.8
50%
Средний
больше 2 лет назад

Уязвимостей на страницу