DEBIAN-CVE-2022-39261

Source
https://security-tracker.debian.org/tracker/CVE-2022-39261
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-39261.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2022-39261
Upstream
Published
2022-09-28T14:15:10.827Z
Modified
2025-11-20T10:16:01.163492Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem loader loads templates for which the name is a user input. It is possible to use the source or include statement to read arbitrary files from outside the templates' directory when using a namespace like @somewhere/../some.file. In such a case, validation is bypassed. Versions 1.44.7, 2.15.3, and 3.4.3 contain a fix for validation of such template names. There are no known workarounds aside from upgrading.

References

Affected packages

Debian:11 / php-twig

Package

Name
php-twig
Purl
pkg:deb/debian/php-twig?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.14.3-1+deb11u2

Affected versions

2.*

2.14.3-1
2.14.3-1+deb11u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / php-twig

Package

Name
php-twig
Purl
pkg:deb/debian/php-twig?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.4.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / php-twig

Package

Name
php-twig
Purl
pkg:deb/debian/php-twig?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.4.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / php-twig

Package

Name
php-twig
Purl
pkg:deb/debian/php-twig?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.4.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}