A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place.
{ "binaries": [ { "binary_version": "1.23.1-1ubuntu4+esm1", "binary_name": "php-twig" } ], "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro" }
{ "binaries": [ { "binary_version": "2.4.6-1ubuntu0.1~esm1", "binary_name": "php-twig" } ], "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro" }