Skip to content

nokaut-offers-box1.4.0: 1 vulnerabilities (highest severity is: 2.2) #30

Description

@mend-bolt-for-github
Vulnerable Library - nokaut-offers-box1.4.0

Library home page: https://plugins.svn.wordpress.org/nokaut-offers-box

Found in HEAD commit: aa67e5c8feb26ac6176ddfd4899d3ecd6eb82bb3

Vulnerable Source Files (1)

/vendor/twig/twig/src/Extension/SandboxExtension.php

Vulnerabilities

Vulnerability Severity CVSS Dependency Type Fixed in (nokaut-offers-box1.4.0 version) Remediation Possible**
CVE-2024-51754 Low 2.2 nokaut-offers-box1.4.0 Direct twig/twig-3.11.2,3.14.1

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

CVE-2024-51754

Vulnerable Library - nokaut-offers-box1.4.0

Library home page: https://plugins.svn.wordpress.org/nokaut-offers-box

Found in HEAD commit: aa67e5c8feb26ac6176ddfd4899d3ecd6eb82bb3

Found in base branch: main

Vulnerable Source Files (1)

/vendor/twig/twig/src/Extension/SandboxExtension.php

Vulnerability Details

Twig is a template language for PHP. In a sandbox, an attacker can call "__toString()" on an object even if the "__toString()" method is not allowed by the security policy when the object is part of an array or an argument list (arguments to a function or a filter for instance). This issue has been patched in versions 3.11.2 and 3.14.1. All users are advised to upgrade. There are no known workarounds for this issue.

Publish Date: 2024-11-06

URL: CVE-2024-51754

CVSS 3 Score Details (2.2)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: High
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-6377-hfv9-hqf6

Release Date: 2024-11-06

Fix Resolution: twig/twig-3.11.2,3.14.1

Step up your Open Source Security Game with Mend here

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions