Vulnerabilities (CVE)

Filtered by vendor Symfony Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-9942 1 Symfony 1 Twig 2021-07-21 4.3 MEDIUM 3.7 LOW
A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place.