{"id":"GHSA-5mv2-rx3q-4w2v","summary":"Code injection in Twig","details":"# Description\n\nWhen in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions.\n\n# Resolution\n\nWe now disallow calling non Closure in the `sort` filter like we already did for some other filters.\n\n# Credits\n\nWe would like to thank Marlon Starkloff for reporting the issue and Fabien Potencier for fixing the issue.\n ","aliases":["CVE-2022-23614"],"modified":"2024-02-15T05:34:22.119618Z","published":"2022-02-10T22:21:48Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-02-07T16:43:09Z","nvd_published_at":"2022-02-04T23:15:00Z","cwe_ids":["CWE-74","CWE-94"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/twigphp/Twig/security/advisories/GHSA-5mv2-rx3q-4w2v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23614"},{"type":"WEB","url":"https://github.com/twigphp/Twig/commit/22b9dc3c03ee66d7e21d9ed2ca76052b134cb9e9"},{"type":"WEB","url":"https://github.com/twigphp/Twig/commit/2eb33080558611201b55079d07ac88f207b466d5"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/twig/twig/CVE-2022-23614.yaml"},{"type":"WEB","url":"https://github.com/twigphp/Twig"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I2PVV5DUTRUECTIHMTWRI5Z7DVNYQ2YO"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OTN4273U4RHVIXED64T7DSMJ3VYTPRE7"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PECHIY2XLWUH2WLCNPDGNFMPHPRPCEDZ"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SIGZCFSYLPP7UVJ4E4NLHSOQSKYNXSAD"},{"type":"WEB","url":"https://symfony.com/blog/twig-security-release-disallow-non-closures-in-the-sort-filter"},{"type":"WEB","url":"https://www.debian.org/security/2022/dsa-5107"}],"affected":[{"package":{"name":"twig/twig","ecosystem":"Packagist","purl":"pkg:composer/twig/twig"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.14.11"}]}],"versions":["v2.0.0","v2.1.0","v2.10.0","v2.11.0","v2.11.1","v2.11.2","v2.11.3","v2.12.0","v2.12.1","v2.12.2","v2.12.3","v2.12.4","v2.12.5","v2.13.0","v2.13.1","v2.14.0","v2.14.1","v2.14.10","v2.14.2","v2.14.3","v2.14.4","v2.14.5","v2.14.6","v2.14.7","v2.14.8","v2.14.9","v2.2.0","v2.3.0","v2.3.1","v2.3.2","v2.4.0","v2.4.1","v2.4.2","v2.4.3","v2.4.4","v2.4.5","v2.4.6","v2.4.7","v2.4.8","v2.5.0","v2.6.0","v2.6.1","v2.6.2","v2.7.0","v2.7.1","v2.7.2","v2.7.3","v2.7.4","v2.8.0","v2.8.1","v2.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-5mv2-rx3q-4w2v/GHSA-5mv2-rx3q-4w2v.json"}},{"package":{"name":"twig/twig","ecosystem":"Packagist","purl":"pkg:composer/twig/twig"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.3.8"}]}],"versions":["v3.0.0","v3.0.1","v3.0.2","v3.0.3","v3.0.4","v3.0.5","v3.1.0","v3.1.1","v3.2.1","v3.3.0","v3.3.1","v3.3.2","v3.3.3","v3.3.4","v3.3.5","v3.3.6","v3.3.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-5mv2-rx3q-4w2v/GHSA-5mv2-rx3q-4w2v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}