A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place.
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.23.1-1ubuntu4+esm1", "binary_name": "php-twig" }, { "binary_version": "1.23.1-1ubuntu4+esm1", "binary_name": "php-twig-doc" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.4.6-1ubuntu0.1~esm1", "binary_name": "php-twig" }, { "binary_version": "2.4.6-1ubuntu0.1~esm1", "binary_name": "php-twig-doc" } ] }