First published: Wed Aug 12 2015(Updated: )
Remote code execution in templates
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/twig/twig | <1.20.0 | |
composer/twig/twig | <1.20.0 | 1.20.0 |
symfony Twig | <=1.19.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7809 has a high severity rating due to its potential for remote code execution.
To fix CVE-2015-7809, upgrade Twig to version 1.20.0 or later.
CVE-2015-7809 affects versions of the Twig templating engine prior to 1.20.0 when Sandbox mode is enabled.
CVE-2015-7809 allows remote attackers to execute arbitrary code within applications that use vulnerable versions of Twig.
If upgrading is not possible, consider disabling Sandbox mode to mitigate the risk posed by CVE-2015-7809.