Skip to content

Multiple command injections via malicious git/hg branch names

High
Seldaek published GHSA-v9qv-c7wm-wgmf Jun 10, 2024

Package

composer composer/composer (Composer)

Affected versions

>=2.0,<2.2.24 || >=2.3,<2.7.7

Patched versions

2.2.24, 2.7.7

Description

Impact

The composer install command running inside a git/hg repository which has specially crafted branch names can lead to command injection. So this requires cloning untrusted repositories.

Patches

2.2.24 for 2.2 LTS or 2.7.7 for mainline

Workarounds

Avoid cloning potentially compromised repositories.

Severity

High

CVE ID

CVE-2024-35242

Weaknesses

No CWEs

Credits