CVE-2019-9942
23.03.2019, 15:29
A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place.Enginsight
Vendor | Product | Version |
---|---|---|
symfony | twig | 𝑥 < 1.38.0 |
symfony | twig | 2.0.0 ≤ 𝑥 < 2.7.0 |
debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
php-twig |
| ||||||||||||||||||||||||||
twig |
|
References