Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-41116

Опубликовано: 05 окт. 2021
Источник: ubuntu
Приоритет: negligible
CVSS2: 7.5
CVSS3: 8.2

Описание

Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. The issue has been resolved in composer versions 1.10.23 and 2.1.9. There are no workarounds for this issue.

РелизСтатусПримечание
bionic

not-affected

devel

not-affected

esm-apps/bionic

not-affected

esm-apps/focal

not-affected

esm-apps/jammy

not-affected

esm-apps/noble

not-affected

esm-apps/xenial

needed

esm-infra-legacy/trusty

DNE

focal

not-affected

hirsute

not-affected

Показывать по

7.5 High

CVSS2

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
nvd
больше 4 лет назад

Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. The issue has been resolved in composer versions 1.10.23 and 2.1.9. There are no workarounds for this issue.

CVSS3: 8.2
debian
больше 4 лет назад

Composer is an open source dependency manager for the PHP language. In ...

CVSS3: 8.2
github
больше 4 лет назад

Improper escaping of command arguments on Windows leading to command injection

suse-cvrf
больше 3 лет назад

Security update for php-composer

7.5 High

CVSS2

8.2 High

CVSS3