VDB
Sign up
HIGH8.8

GHSA-v9qv-c7wm-wgmf

Composer has multiple command injections via malicious git/hg branch names

Quick fix

GHSA-v9qv-c7wm-wgmf — composer/composer: upgrade to the fixed version with the command below.

composer require composer/composer:^2.2.24

Details

### Impact

The `composer install` command running inside a git/hg repository which has specially crafted branch names can lead to command injection. So this requires cloning untrusted repositories.

### Patches

2.2.24 for 2.2 LTS or 2.7.7 for mainline

### Workarounds

Avoid cloning potentially compromised repositories.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/composer/composer
Introduced in: 2.0Fixed in: 2.2.24
Fixcomposer require composer/composer:^2.2.24
Packagist/composer/composer
Introduced in: 2.3Fixed in: 2.7.7
Fixcomposer require composer/composer:^2.7.7

References