Candidate: CVE-2021-23803 PublicDate: 2021-12-17 20:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23803 https://github.com/nette/latte/commit/227c86eda9a8a6d060ea8501923e768b6d992210 https://github.com/nette/latte/issues/279 https://snyk.io/vuln/SNYK-PHP-LATTELATTE-1932226 Description: This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the security of the application. When the template is set to allow/disallow the use of certain functions, adding control characters (x00-x08) after the function will bypass these restrictions. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_php-nette: upstream_php-nette: needs-triage trusty_php-nette: ignored (out of standard support) xenial_php-nette: ignored (out of standard support) bionic_php-nette: needs-triage