VulnerabilityModified
CVE-2015-7809
The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute arbitrary code via the _self variable in a template.
MEDIUM 6.8EPSS 3.40%
Does this matter?
Lower severity and a low EPSS score (3.40%). Track it; it rarely justifies an emergency change on its own.
Description
The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute arbitrary code via the _self variable in a template.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 3.40% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- symfony/twig
- Source
- cve@mitre.org
References
- http://openwall.com/lists/oss-security/2015/08/21/3
- http://openwall.com/lists/oss-security/2015/10/11/2
- http://symfony.com/blog/security-release-twig-1-20-0Vendor Advisory
- http://www.debian.org/security/2015/dsa-3343
- https://github.com/fabpot/Twig/commit/30be07759a3de2558da5224f127d052ecf492e8f
- https://github.com/twigphp/Twig/pull/1759
- http://openwall.com/lists/oss-security/2015/08/21/3
- http://openwall.com/lists/oss-security/2015/10/11/2
- http://symfony.com/blog/security-release-twig-1-20-0Vendor Advisory
- http://www.debian.org/security/2015/dsa-3343
- https://github.com/fabpot/Twig/commit/30be07759a3de2558da5224f127d052ecf492e8f
- https://github.com/twigphp/Twig/pull/1759
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.