CVE-2019-9942
23.03.2019, 15:29
A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place.Enginsight
| Vendor | Product | Version |
|---|---|---|
| symfony | twig | 𝑥 < 1.38.0 |
| symfony | twig | 2.0.0 ≤ 𝑥 < 2.7.0 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| php-twig |
| ||||||||||||||||||||||||||
| twig |
|
References