Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-41116

Опубликовано: 05 окт. 2021
Источник: nvd
CVSS3: 8.2
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. The issue has been resolved in composer versions 1.10.23 and 2.1.9. There are no workarounds for this issue.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:getcomposer:composer:*:*:*:*:*:*:*:*
Версия до 1.10.23 (исключая)
cpe:2.3:a:getcomposer:composer:*:*:*:*:*:*:*:*
Версия от 2.0.0 (включая) до 2.1.9 (исключая)
Конфигурация 2
cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:*
Версия до 5.21.0 (исключая)

EPSS

Процентиль: 76%
0.00975
Низкий

8.2 High

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-77
CWE-77

Связанные уязвимости

CVSS3: 8.2
ubuntu
больше 4 лет назад

Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. The issue has been resolved in composer versions 1.10.23 and 2.1.9. There are no workarounds for this issue.

CVSS3: 8.2
debian
больше 4 лет назад

Composer is an open source dependency manager for the PHP language. In ...

CVSS3: 8.2
github
больше 4 лет назад

Improper escaping of command arguments on Windows leading to command injection

suse-cvrf
больше 3 лет назад

Security update for php-composer

EPSS

Процентиль: 76%
0.00975
Низкий

8.2 High

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-77
CWE-77