Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-frqg-7g38-6gcf

Опубликовано: 05 окт. 2021
Источник: github
Github: Прошло ревью
CVSS3: 8.2

Описание

Improper escaping of command arguments on Windows leading to command injection

Impact

Windows users running Composer to install untrusted dependencies are affected and should definitely upgrade for safety. Other OSs and WSL are not affected.

Patches

1.10.23 and 2.1.9 fix the issue

Workarounds

None

Пакеты

Наименование

composer/composer

composer
Затронутые версииВерсия исправления

< 1.10.23

1.10.23

Наименование

composer/composer

composer
Затронутые версииВерсия исправления

>= 2.0.0-alpha1, < 2.1.9

2.1.9

EPSS

Процентиль: 72%
0.0072
Низкий

8.2 High

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 8.2
ubuntu
больше 4 лет назад

Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. The issue has been resolved in composer versions 1.10.23 and 2.1.9. There are no workarounds for this issue.

CVSS3: 8.2
nvd
больше 4 лет назад

Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. The issue has been resolved in composer versions 1.10.23 and 2.1.9. There are no workarounds for this issue.

CVSS3: 8.2
debian
больше 4 лет назад

Composer is an open source dependency manager for the PHP language. In ...

suse-cvrf
больше 3 лет назад

Security update for php-composer

EPSS

Процентиль: 72%
0.0072
Низкий

8.2 High

CVSS3

Дефекты

CWE-77