Логотип exploitDog
bind:CVE-2022-24828
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-24828

Количество 8

Количество 8

ubuntu логотип

CVE-2022-24828

около 3 лет назад

Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::getFileContent` can have a code injection vulnerability if the user can control the `$file` or `$identifier` argument. This leads to a vulnerability on packagist.org for example where the composer.json's `readme` field can be used as a vector for injecting parameters into hg/Mercurial via the `$file` argument, or git via the `$identifier` argument if you allow arbitrary data there (Packagist does not, but maybe other integrators do). Composer itself should not be affected by the vulnerability as it does not call `getFileContent` with arbitrary data into `$file`/`$identifier`. To the best of our knowledge this was not abused, and the vulnerability has been patched on packagist.org and Private Packagist within a day of the vulnerability report.

CVSS3: 8.3
EPSS: Низкий
nvd логотип

CVE-2022-24828

около 3 лет назад

Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::getFileContent` can have a code injection vulnerability if the user can control the `$file` or `$identifier` argument. This leads to a vulnerability on packagist.org for example where the composer.json's `readme` field can be used as a vector for injecting parameters into hg/Mercurial via the `$file` argument, or git via the `$identifier` argument if you allow arbitrary data there (Packagist does not, but maybe other integrators do). Composer itself should not be affected by the vulnerability as it does not call `getFileContent` with arbitrary data into `$file`/`$identifier`. To the best of our knowledge this was not abused, and the vulnerability has been patched on packagist.org and Private Packagist within a day of the vulnerability report.

CVSS3: 8.3
EPSS: Низкий
debian логотип

CVE-2022-24828

около 3 лет назад

Composer is a dependency manager for the PHP programming language. Int ...

CVSS3: 8.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3020-1

почти 3 года назад

Security update for php-composer2

EPSS: Низкий
github логотип

GHSA-x7cr-6qr6-2hh6

около 3 лет назад

Missing input validation can lead to command execution in composer

CVSS3: 8.3
EPSS: Низкий
fstec логотип

BDU:2022-02944

около 3 лет назад

Уязвимость реализации метода VcsDriver::getFileContent() менеджера зависимостей для PHP Composer, позволяющая нарушителю выполнить произвольные команды

CVSS3: 8.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:0132-1

около 3 лет назад

Security update for php-composer

EPSS: Низкий
redos логотип

ROS-20240626-10

около 1 года назад

Множественные уязвимости composer

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-24828

Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::getFileContent` can have a code injection vulnerability if the user can control the `$file` or `$identifier` argument. This leads to a vulnerability on packagist.org for example where the composer.json's `readme` field can be used as a vector for injecting parameters into hg/Mercurial via the `$file` argument, or git via the `$identifier` argument if you allow arbitrary data there (Packagist does not, but maybe other integrators do). Composer itself should not be affected by the vulnerability as it does not call `getFileContent` with arbitrary data into `$file`/`$identifier`. To the best of our knowledge this was not abused, and the vulnerability has been patched on packagist.org and Private Packagist within a day of the vulnerability report.

CVSS3: 8.3
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-24828

Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::getFileContent` can have a code injection vulnerability if the user can control the `$file` or `$identifier` argument. This leads to a vulnerability on packagist.org for example where the composer.json's `readme` field can be used as a vector for injecting parameters into hg/Mercurial via the `$file` argument, or git via the `$identifier` argument if you allow arbitrary data there (Packagist does not, but maybe other integrators do). Composer itself should not be affected by the vulnerability as it does not call `getFileContent` with arbitrary data into `$file`/`$identifier`. To the best of our knowledge this was not abused, and the vulnerability has been patched on packagist.org and Private Packagist within a day of the vulnerability report.

CVSS3: 8.3
1%
Низкий
около 3 лет назад
debian логотип
CVE-2022-24828

Composer is a dependency manager for the PHP programming language. Int ...

CVSS3: 8.3
1%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3020-1

Security update for php-composer2

1%
Низкий
почти 3 года назад
github логотип
GHSA-x7cr-6qr6-2hh6

Missing input validation can lead to command execution in composer

CVSS3: 8.3
1%
Низкий
около 3 лет назад
fstec логотип
BDU:2022-02944

Уязвимость реализации метода VcsDriver::getFileContent() менеджера зависимостей для PHP Composer, позволяющая нарушителю выполнить произвольные команды

CVSS3: 8.3
1%
Низкий
около 3 лет назад
suse-cvrf логотип
openSUSE-SU-2022:0132-1

Security update for php-composer

около 3 лет назад
redos логотип
ROS-20240626-10

Множественные уязвимости composer

CVSS3: 8.8
около 1 года назад

Уязвимостей на страницу