Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Multiple command injections via malicious git/hg branch names

High
Seldaek published GHSA-v9qv-c7wm-wgmf Jun 10, 2024

Package

composer/composer (Composer)

Affected versions

>=2.0,<2.2.24 || >=2.3,<2.7.7

Patched versions

2.2.24, 2.7.7

Description

Impact

The composer install command running inside a git/hg repository which has specially crafted branch names can lead to command injection. So this requires cloning untrusted repositories.

Patches

2.2.24 for 2.2 LTS or 2.7.7 for mainline

Workarounds

Avoid cloning potentially compromised repositories.

Severity

High

CVE ID

CVE-2024-35242

Weaknesses

No CWEs

Credits

Morty Proxy This is a proxified and sanitized view of the page, visit original site.