DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2024-35241

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-35241

CGA ID

CGA-g75w-3gxm-gj8g

Severity

8.8

High

CVSS V3

Summary

Composer has a command injection via malicious git branch name

Description

Impact

The status, reinstall and remove commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code.

Patches

2.2.24 for 2.2 LTS or 2.7.7 for mainline

Workarounds

Avoid installing dependencies via git by using --prefer-dist or the preferred-install: dist config setting.

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images