VDB
Sign up
HIGH8.8

GHSA-47f6-5gq3-vx9c

Composer has a command injection via malicious git branch name

Quick fix

GHSA-47f6-5gq3-vx9c — composer/composer: upgrade to the fixed version with the command below.

composer require composer/composer:^2.2.24

Details

### Impact

The `status`, `reinstall` and `remove` commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code.

### Patches

2.2.24 for 2.2 LTS or 2.7.7 for mainline

### Workarounds

Avoid installing dependencies via git by using `--prefer-dist` or the `preferred-install: dist` config setting.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/composer/composer
Introduced in: 2.0Fixed in: 2.2.24
Fixcomposer require composer/composer:^2.2.24
Packagist/composer/composer
Introduced in: 2.3Fixed in: 2.7.7
Fixcomposer require composer/composer:^2.7.7

References