Vulnerability Description
Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. They are now checked via the property policy and the `__isset()` method is now called after the security check. This is a BC break. This issue has been patched in versions 3.11.2 and 3.14.1. All users are advised to upgrade. There are no known workarounds for this issue.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://github.com/twigphp/Twig/commit/831c148e786178e5f2fde9db67266be3bf241c21
- https://github.com/twigphp/Twig/security/advisories/GHSA-jjxq-ff2g-95vh
FAQ
What is CVE-2024-51755?
CVE-2024-51755 is a vulnerability with a CVSS score of 2.2 (LOW). Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. They are now checked via the property policy...
How severe is CVE-2024-51755?
CVE-2024-51755 has been rated LOW with a CVSS base score of 2.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-51755?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.