Improper Input Validation Affecting twig/twig package, versions >=2.1.0, <2.14.11 >=3.0.1, <3.3.8
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
1.91% (89th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PHP-TWIGTWIG-2395370
- published 6 Feb 2022
- disclosed 6 Feb 2022
- credit Marlon Starkloff
Introduced: 6 Feb 2022
CVE-2022-23614 Open this link in a new tabHow to fix?
Upgrade twig/twig
to version 2.14.11, 3.3.8 or higher.
Overview
twig/twig is a flexible, fast, and secure template language for PHP.
Affected versions of this package are vulnerable to Improper Input Validation via the arrow
parameter of the sort
filter that is not properly enforced. Attackers can abuse this in order to run arbitrary PHP code.
References
CVSS Scores
version 3.1