​
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-cf8c-xqvc-jhcx

Published

Last updated

https://images.chainguard.dev/security/CGA-cf8c-xqvc-jhcx
Package

composer

Latest Update
Fixed
Fixed Version

2.7.7-r0

Aliases
  • CVE-2024-35242
  • GHSA-v9qv-c7wm-wgmf

Severity

8.8

High

CVSS V3

Summary

Composer has multiple command injections via malicious git/hg branch names

Description

Impact

The composer install command running inside a git/hg repository which has specially crafted branch names can lead to command injection. So this requires cloning untrusted repositories.

Patches

2.2.24 for 2.2 LTS or 2.7.7 for mainline

Workarounds

Avoid cloning potentially compromised repositories.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images