CVE-2025-24374

MEDIUM4.3EPSS 0.30%

Twig security issue where escaping was missing when using null coalesce operator

發布日:2025/1/29修改日:2026/5/27
也稱為:GHSA-3xg3-cgvq-2xwrDEBIAN-CVE-2025-24374

描述

Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

參考連結(7)