CVE-2024-51755
LOWDescription
Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. They are now checked via the property policy and the `__isset()` method is now called after the security check. This is a BC break. This issue has been patched in versions 3.11.2 and 3.14.1. All users are advised to upgrade. There are no known workarounds for this issue.
Is your site exposed to CVE-2024-51755?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2024-51755? +
How severe is CVE-2024-51755? +
How do I check if I'm vulnerable to CVE-2024-51755? +
Related Vulnerabilities
The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backend user with permission …
A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine API via …
Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with …
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Prior to 2.4.0, …
Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece …
Improper resource exposure in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass site isolation via …