First published: Wed Sep 28 2022(Updated: )
Possibility to load a template outside a configured directory when using the filesystem loader
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/twig/twig | >=1.0.0<1.44.7>=2.0.0<2.15.3>=3.0.0<3.4.3 | |
Symfony Twig | >=1.0.0<1.44.7 | |
Symfony Twig | >=2.0.0<2.15.3 | |
Symfony Twig | >=3.0.0<3.4.3 | |
Drupal Drupal | >=8.0.0<9.3.22 | |
Drupal Drupal | >=9.4.0<9.4.7 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
Fedoraproject Fedora | =37 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
debian/php-twig | 2.14.3-1+deb11u2 3.5.1-1 3.7.1-1 | |
debian/twig | <=2.6.2-2 | 2.6.2-2+deb10u1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-39261 is a vulnerability that allows the loading of a template outside of a configured directory when using the filesystem loader in Twig.
The Twig package versions 1.0.0 to 1.44.7, 2.0.0 to 2.15.3, and 3.0.0 to 3.4.3 are affected by CVE-2022-39261.
The severity of CVE-2022-39261 is moderate.
To fix CVE-2022-39261, upgrade the Twig package to a version higher than 1.44.7, 2.15.3, or 3.4.3.
You can find more information about CVE-2022-39261 at the following reference link: [https://symfony.com/blog/twig-security-release-possibility-to-load-a-template-outside-a-configured-directory-when-using-the-filesystem-loader](https://symfony.com/blog/twig-security-release-possibility-to-load-a-template-outside-a-configured-directory-when-using-the-filesystem-loader)