SCA: security update for twig/twig (GHSA-5mv2-rx3q-4w2v)

critical Tenable Cloud Security Plugin ID 410931

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the
`sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected
versions this constraint was not properly enforced and could lead to code injection of arbitrary PHP code.
Patched versions now disallow calling non Closure in the `sort` filter as is the case for some other
filters. Users are advised to upgrade. (CVE-2022-23614)

See Also

https://github.com/advisories/GHSA-5mv2-rx3q-4w2v

Plugin Details

Severity: Critical

ID: 410931

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.48

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2022-23614

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2/10/2022

Vulnerability Publication Date: 2/4/2022

Reference Information

CVE: CVE-2022-23614