Количество 7
Количество 7
GHSA-jm6m-4632-36hf
Composer Remote Code Execution vulnerability via web-accessible composer.phar

CVE-2023-43655
Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a php file may be subject to a remote code execution vulnerability if PHP also has `register_argc_argv` enabled in php.ini. Versions 2.6.4, 2.2.22 and 1.10.27 patch this vulnerability. Users are advised to upgrade. Users unable to upgrade should make sure `register_argc_argv` is disabled in php.ini, and avoid publishing composer.phar to the web as this is not best practice.

CVE-2023-43655
Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a php file may be subject to a remote code execution vulnerability if PHP also has `register_argc_argv` enabled in php.ini. Versions 2.6.4, 2.2.22 and 1.10.27 patch this vulnerability. Users are advised to upgrade. Users unable to upgrade should make sure `register_argc_argv` is disabled in php.ini, and avoid publishing composer.phar to the web as this is not best practice.
CVE-2023-43655
Composer is a dependency manager for PHP. Users publishing a composer. ...

SUSE-SU-2023:4041-1
Security update for php-composer2

BDU:2024-04879
Уязвимость файла composer.phar менеджера зависимостей для PHP Composer, позволяющая нарушителю выполнить произвольные команды

ROS-20240626-10
Множественные уязвимости composer
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-jm6m-4632-36hf Composer Remote Code Execution vulnerability via web-accessible composer.phar | CVSS3: 8.8 | 3% Низкий | больше 1 года назад | |
![]() | CVE-2023-43655 Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a php file may be subject to a remote code execution vulnerability if PHP also has `register_argc_argv` enabled in php.ini. Versions 2.6.4, 2.2.22 and 1.10.27 patch this vulnerability. Users are advised to upgrade. Users unable to upgrade should make sure `register_argc_argv` is disabled in php.ini, and avoid publishing composer.phar to the web as this is not best practice. | CVSS3: 6.4 | 3% Низкий | больше 1 года назад |
![]() | CVE-2023-43655 Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a php file may be subject to a remote code execution vulnerability if PHP also has `register_argc_argv` enabled in php.ini. Versions 2.6.4, 2.2.22 and 1.10.27 patch this vulnerability. Users are advised to upgrade. Users unable to upgrade should make sure `register_argc_argv` is disabled in php.ini, and avoid publishing composer.phar to the web as this is not best practice. | CVSS3: 6.4 | 3% Низкий | больше 1 года назад |
CVE-2023-43655 Composer is a dependency manager for PHP. Users publishing a composer. ... | CVSS3: 6.4 | 3% Низкий | больше 1 года назад | |
![]() | SUSE-SU-2023:4041-1 Security update for php-composer2 | 3% Низкий | больше 1 года назад | |
![]() | BDU:2024-04879 Уязвимость файла composer.phar менеджера зависимостей для PHP Composer, позволяющая нарушителю выполнить произвольные команды | CVSS3: 8.8 | 3% Низкий | больше 1 года назад |
![]() | ROS-20240626-10 Множественные уязвимости composer | CVSS3: 8.8 | около 1 года назад |
Уязвимостей на страницу