twig/twig has a possible sandbox bypass <v3.14.0

Created on 10 September 2024, 7 months ago
Updated 21 September 2024, 7 months ago

Problem/Motivation

twig/twig Released version 3.14.0 (See https://github.com/twigphp/Twig/releases/tag/v3.14.0)
which addressed the security issue https://github.com/advisories/GHSA-6j75-5wfj-gh66

Not able to update on drupal 10.3.3 sites

$ lando composer why twig/twig
chi-teck/drupal-code-generator 3.6.1   requires  twig/twig (^3.4)     
drupal/core-recommended        10.3.3  requires  twig/twig (~v3.10.2) 
drupal/twig_tweak              3.4.0   requires  twig/twig (^3.10.3)  
symfony/http-kernel            v6.4.11 conflicts twig/twig (<2.13)   

because drupal/core-recommended sticking with v3.10.*

Steps to reproduce

Proposed resolution

Remaining tasks

User interface changes

Introduced terminology

API changes

Data model changes

Release notes snippet

πŸ“Œ Task
Status

Fixed

Version

10.2 ✨

Component
BaseΒ  β†’

Last updated about 9 hours ago

Created by

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024