CVE-2019-9942Sensitive Information Exposure in Twig

Severity
3.7LOWNVD
EPSS
0.4%
top 38.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 23
Latest updateMar 13

Description

A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 2.2 | Impact: 1.4

Affected Packages3 packages

Packagisttwig/twig2.0.02.7.0+1
NVDsymfony/twig2.0.02.7.0+1
Ubuntutwig/twig< 1.23.1-1ubuntu4+esm1+1

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

5
OSV
php-twig, twig vulnerabilities2023-03-13
GHSA
Twig Sandbox Information Disclosure2022-03-26
OSV
Twig Sandbox Information Disclosure2022-03-26
OSV
CVE-2019-9942: A sandbox information disclosure exists in Twig before 12019-03-23
CVEList
CVE-2019-9942: A sandbox information disclosure exists in Twig before 12019-03-23

📋Vendor Advisories

1
Ubuntu
Twig vulnerabilities2023-03-13

💬Community

3
Bugzilla
CVE-2019-9942 php-twig: sandbox information disclosure [epel-all]2019-03-26
Bugzilla
CVE-2019-9942 php-twig: sandbox information disclosure [fedora-all]2019-03-26
Bugzilla
CVE-2019-9942 php-twig: sandbox information disclosure2019-03-26
CVE-2019-9942 — Sensitive Information Exposure in Twig | cvebase