Lucene search

K
osvGoogleOSV:GHSA-W5HR-JM4J-9JVQ
HistoryMar 02, 2021 - 2:57 a.m.

Sandbox escape through template_object in smarty

2021-03-0202:57:23
Google
osv.dev
65
sandbox escape
template object
smarty
upgrade
software security

EPSS

0.002

Percentile

53.0%

Sandbox protection could be bypassed through access to an internal Smarty object that should have been blocked. Sites that rely on Smarty Security features should upgrade as soon as possible. Please upgrade to 3.1.39 or higher.