Affected versions
Twig >1.0.0,1.44.7 || >2.0.0,2.15.3 || >3.0.0,3.4.3 are affected by this security issue.
The issue has been fixed in Twig 1.44.7, 2.15.3 and 3.4.3.
Description
When using the filesystem loader to load templates for which the name is a user input, it is possible to use the source
or include
statement to read arbitrary files from outside the templates directory when using a namesp
This week, Symfony development activity focused on finishing and polishing some new features for the upcoming Symfony 6.2 version, such us: updating codebase to use modern PHP features like null coalescing assignment and match statements; adding
The SymfonyCon Disneyland Paris 2022 will start with 2 days of pre-conference workshops organized
Sentry, Twilio, JetBrains PhpStorm, SensioLabs, NetGen Layouts, Les-Tilleuls.coop, … and other fantastic partners will join us at our big next event: SymfonyCon Disneyland Paris 2022!
Want to support us? Are you looking for great Symfony developers?
Join us and become a sponsor of the Sy
This week, development activity focused on tweaking and finishing some of the new features of Symfony 6.2, to be released at the end of November 2022. In addition to a new ChainUserChecker that allows calling multiple user checkers for a firewall, we merged the Sy
As this event approaches we are pleased to announce you the next person joining the speaker team: