HIGH8.8
GHSA-v9qv-c7wm-wgmf
Composer has multiple command injections via malicious git/hg branch names
Quick fix
GHSA-v9qv-c7wm-wgmf — composer/composer: upgrade to the fixed version with the command below.
composer require composer/composer:^2.2.24Details
### Impact
The `composer install` command running inside a git/hg repository which has specially crafted branch names can lead to command injection. So this requires cloning untrusted repositories.
### Patches
2.2.24 for 2.2 LTS or 2.7.7 for mainline
### Workarounds
Avoid cloning potentially compromised repositories.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/composer/composer
Introduced in:
2.0Fixed in: 2.2.24Fix
composer require composer/composer:^2.2.24Packagist/composer/composer
Introduced in:
2.3Fixed in: 2.7.7Fix
composer require composer/composer:^2.7.7References
- https://github.com/composer/composer/security/advisories/GHSA-v9qv-c7wm-wgmf[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-35242[ADVISORY]
- https://github.com/composer/composer/commit/6bd43dff859c597c09bd03a7e7d6443822d0a396[WEB]
- https://github.com/composer/composer/commit/fc57b93603d7d90b71ca8ec77b1c8a9171fdb467[WEB]
- https://github.com/composer/composer[PACKAGE]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PO4MU2BC7VR6LMHEX4X7DKGHVFXZV2MC[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VLPJHM2WWSYU2F6KHW2BYFGYL4IGTKHC[WEB]