DEBIAN-CVE-2024-51755

Source
https://security-tracker.debian.org/tracker/CVE-2024-51755
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-51755.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2024-51755
Upstream
Published
2024-11-06T20:15:06Z
Modified
2025-10-14T04:26:00.863328Z
Severity
  • 2.2 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. They are now checked via the property policy and the __isset() method is now called after the security check. This is a BC break. This issue has been patched in versions 3.11.2 and 3.14.1. All users are advised to upgrade. There are no known workarounds for this issue.

References

Affected packages

Debian:11 / php-twig

Package

Name
php-twig
Purl
pkg:deb/debian/php-twig?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.14.3-1
2.14.3-1+deb11u1
2.14.3-1+deb11u2
2.14.3-1+deb11u3
2.14.3-1+deb11u4

3.*

3.0.0~beta1-1
3.0.0-1
3.0.0-2
3.0.1-1
3.0.3-1
3.0.4-1
3.0.5-1
3.1.1-1
3.2.1-1
3.3.0-1
3.3.2-1
3.3.3-1
3.3.3-2~stage1
3.3.3-2
3.3.3-3
3.3.4-1
3.3.6-1
3.3.7-1
3.3.8-1
3.3.8-2
3.3.9-1
3.4.1-1
3.4.2-1
3.4.3-1
3.4.3-2
3.5.0-1
3.5.1-1~bpo11+1
3.5.1-1
3.6.0-1
3.6.1-1
3.7.0-1
3.7.1-1
3.7.1-2
3.7.1-3
3.8.0-1
3.8.0-2
3.8.0-3
3.8.0-4
3.9.3-1
3.10.1-1
3.10.3-1
3.11.0-1
3.13.0-1
3.14.0-1
3.14.0-2
3.14.0-3
3.14.0-4
3.14.2-1
3.14.2-2
3.14.2-3
3.15.0-1
3.15.0-2
3.17.1-1
3.17.1-2
3.18.0-1
3.18.0-2
3.18.0-4
3.18.0-5
3.18.0-6
3.18.0-7
3.19.0-1~bootstrap
3.19.0-1
3.20.0-1~bootstrap
3.20.0-1
3.20.0-2
3.21.1-1
3.21.1-2
3.21.1-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / php-twig

Package

Name
php-twig
Purl
pkg:deb/debian/php-twig?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.5.1-1
3.5.1-1+deb12u1
3.6.0-1
3.6.1-1
3.7.0-1
3.7.1-1
3.7.1-2
3.7.1-3
3.8.0-1
3.8.0-2
3.8.0-3
3.8.0-4
3.9.3-1
3.10.1-1
3.10.3-1
3.11.0-1
3.13.0-1
3.14.0-1
3.14.0-2
3.14.0-3
3.14.0-4
3.14.2-1
3.14.2-2
3.14.2-3
3.15.0-1
3.15.0-2
3.17.1-1
3.17.1-2
3.18.0-1
3.18.0-2
3.18.0-4
3.18.0-5
3.18.0-6
3.18.0-7
3.19.0-1~bootstrap
3.19.0-1
3.20.0-1~bootstrap
3.20.0-1
3.20.0-2
3.21.1-1
3.21.1-2
3.21.1-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / php-twig

Package

Name
php-twig
Purl
pkg:deb/debian/php-twig?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.14.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / php-twig

Package

Name
php-twig
Purl
pkg:deb/debian/php-twig?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.14.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}