Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-0128 | Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0. |
Github GHSA |
GHSA-3xg3-cgvq-2xwr | Twig security issue where escaping was missing when using null coalesce operator |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 29 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Jan 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0. | |
| Title | Twig fixes a security issue where escaping was missing when using null coalesce operator (??) | |
| Weaknesses | CWE-74 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-29T15:44:49.358Z
Reserved: 2025-01-20T15:18:26.992Z
Link: CVE-2025-24374
Updated: 2025-01-29T15:44:00.628Z
Status : Received
Published: 2025-01-29T16:15:44.090
Modified: 2025-01-29T16:15:44.090
Link: CVE-2025-24374
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA