detain / datacentered

0 stars 0 forks source link

CVE-2024-45411 (High) detected in twig/twig-2.x-dev #26

Open mend-bolt-for-github[bot] opened 1 month ago

mend-bolt-for-github[bot] commented 1 month ago

CVE-2024-45411 - High Severity Vulnerability

Vulnerable Library - twig/twig-2.x-dev

Twig, the flexible, fast, and secure template language for PHP

Library home page: https://api.github.com/repos/twigphp/Twig/zipball/a1d84cfbc1c2f99ee4af361eb0a32dad47723b01

Dependency Hierarchy: - corneltek/cliframework-4.2.0 (Root Library) - corneltek/codegen-dev-master - :x: **twig/twig-2.x-dev** (Vulnerable Library)

Found in HEAD commit: 81f84f058af0cbca57ee22476557ded21c6813aa

Found in base branch: master

Vulnerability Details

Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0.

Publish Date: 2024-09-09

URL: CVE-2024-45411

CVSS 3 Score Details (8.5)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: High - Privileges Required: Low - User Interaction: None - Scope: Changed - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: High - Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://github.com/twigphp/Twig/security/advisories/GHSA-6j75-5wfj-gh66

Release Date: 2024-09-09

Fix Resolution: twig/twig-v1.44.8,v2.16.1,v3.14.0


Step up your Open Source Security Game with Mend here