CVE-2024-51755

unknown
Published 2024-11-06 · Modified 2024-11-12
CVSS v3
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
CVSS v2
VIR risk

Description

Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. They are now checked via the property policy and the `__isset()` method is now called after the security check. This is a BC break. This issue has been patched in versions 3.11.2 and 3.14.1. All users are advised to upgrade. There are no known workarounds for this issue.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2024-51755

OS impact

OSVersionStatusFixed in
debian debianbookwormaffected
debian debianbullseyeaffected
debian debianforkyfixed3.14.2-1
debian debiansidfixed3.14.2-1
debian debiantrixiefixed3.14.2-1

Package impact

EcosystemPackageVulnerableFixed
php Packagisttwig/twig<3.11.23.11.2
php Packagisttwig/twig>=3.12,<3.14.13.14.1

References

Verify integrity in audit chain (admin only). AS-IS.