Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access to system configuration secrets. Attackers with page-edit permission can use co…
High CVSS 7.5
Summary
Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access to system configuration secrets. Attackers with page-edit permission can use config.get() or config.toArray() in Twig templates to retrieve sensitive values like system.cache.redis.password when config_access is enabled.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/getgrav/grav/security/advisories/GHSA-xjw5-q542-3vmr
- https://www.vulncheck.com/advisories/grav-before-information-disclosure-via-twig-sandbox
Timeline
- nvd_ingest NVD