Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-41116

Опубликовано: 05 окт. 2021
Источник: debian
EPSS Низкий

Описание

Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. The issue has been resolved in composer versions 1.10.23 and 2.1.9. There are no workarounds for this issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
composernot-affectedpackage

Примечания

  • https://github.com/composer/composer/security/advisories/GHSA-frqg-7g38-6gcf

  • https://github.com/composer/composer/commit/ca5e2f8d505fd3bfac6f7c85b82f2740becbc0aa

EPSS

Процентиль: 76%
0.00975
Низкий

Связанные уязвимости

CVSS3: 8.2
ubuntu
больше 4 лет назад

Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. The issue has been resolved in composer versions 1.10.23 and 2.1.9. There are no workarounds for this issue.

CVSS3: 8.2
nvd
больше 4 лет назад

Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. The issue has been resolved in composer versions 1.10.23 and 2.1.9. There are no workarounds for this issue.

CVSS3: 8.2
github
больше 4 лет назад

Improper escaping of command arguments on Windows leading to command injection

suse-cvrf
больше 3 лет назад

Security update for php-composer

EPSS

Процентиль: 76%
0.00975
Низкий