CVE-2022-23614

Summary

CVECVE-2022-23614
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2022-02-04 23:15:00 UTC
Updated2023-11-07 03:44:00 UTC
DescriptionTwig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions this constraint was not properly enforced and could lead to code injection of arbitrary PHP code. Patched versions now disallow calling non Closure in the `sort` filter as is the case for some other filters. Users are advised to upgrade.

Risk And Classification

Problem Types: CWE-94

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Operating System Debian Debian Linux 11.0 All All All
Operating System Fedoraproject Fedora 34 All All All
Operating System Fedoraproject Fedora 35 All All All
Application Symfony Twig All All All All

References

ReferenceSourceLinkTags
[SECURITY] Fedora 34 Update: php-twig3-3.3.8-1.fc34 - package-announce - Fedora Mailing-Lists FEDORA lists.fedoraproject.org
bug #3641 Disallow non closures in `sort` filter when the sanbox mode… · twigphp/Twig@22b9dc3 · GitHub MISC github.com
[SECURITY] Fedora 34 Update: php-twig3-3.3.8-1.fc34 - package-announce - Fedora Mailing-Lists lists.fedoraproject.org
[SECURITY] Fedora 34 Update: php-twig2-2.14.11-1.fc34 - package-announce - Fedora Mailing-Lists FEDORA lists.fedoraproject.org
Disallow non closures in `sort` filter when the sanbox mode is enabled · twigphp/Twig@2eb3308 · GitHub MISC github.com
[SECURITY] Fedora 35 Update: php-twig2-2.14.11-1.fc35 - package-announce - Fedora Mailing-Lists lists.fedoraproject.org
Debian -- Security Information -- DSA-5107-1 php-twig DEBIAN www.debian.org
[SECURITY] Fedora 35 Update: php-twig3-3.3.8-1.fc35 - package-announce - Fedora Mailing-Lists lists.fedoraproject.org
[SECURITY] Fedora 35 Update: php-twig2-2.14.11-1.fc35 - package-announce - Fedora Mailing-Lists FEDORA lists.fedoraproject.org
[SECURITY] Fedora 34 Update: php-twig2-2.14.11-1.fc34 - package-announce - Fedora Mailing-Lists lists.fedoraproject.org
Disallow non closures in `sort` filter when the sandbox mode is enabled · Advisory · twigphp/Twig · GitHub CONFIRM github.com
[SECURITY] Fedora 35 Update: php-twig3-3.3.8-1.fc35 - package-announce - Fedora Mailing-Lists FEDORA lists.fedoraproject.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Legacy QID Mappings

  • 179157 Debian Security Update for php-twig (DSA 5107-1)
  • 182133 Debian Security Update for php-twig (CVE-2022-23614)
  • 199472 Ubuntu Security Notification for Twig Vulnerabilities (USN-5947-1)
  • 282377 Fedora Security Update for Hypertext Preprocessor (PHP) (FEDORA-2022-167b9becef)
  • 282378 Fedora Security Update for Hypertext Preprocessor (PHP) (FEDORA-2022-7d871d7583)
  • 282379 Fedora Security Update for Hypertext Preprocessor (PHP) (FEDORA-2022-58abb323f0)
  • 282380 Fedora Security Update for Hypertext Preprocessor (PHP) (FEDORA-2022-47293b1d23)
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report