​
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-g75w-3gxm-gj8g

Published

Last updated

https://images.chainguard.dev/security/CGA-g75w-3gxm-gj8g
Package

composer

Latest Update
Fixed
Fixed Version

2.7.7-r0

Aliases
  • CVE-2024-35241
  • GHSA-47f6-5gq3-vx9c

Severity

8.8

High

CVSS V3

Summary

Composer has a command injection via malicious git branch name

Description

Impact

The status, reinstall and remove commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code.

Patches

2.2.24 for 2.2 LTS or 2.7.7 for mainline

Workarounds

Avoid installing dependencies via git by using --prefer-dist or the preferred-install: dist config setting.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images