PT-2021-23100 · Composer+1 · Composer+1

Paul Gerste

·

Published

2021-10-05

·

Updated

2024-06-15

·

CVE-2021-41116

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Composer versions prior to 1.10.23 Composer versions prior to 2.1.9
Description The issue affects Windows users running Composer to install untrusted dependencies, subjecting them to command injection. Other operating systems and Windows Subsystem for Linux (WSL) are not affected.
Recommendations For versions prior to 1.10.23, upgrade to version 1.10.23 or later. For versions prior to 2.1.9, upgrade to version 2.1.9 or later. As a temporary workaround, consider avoiding the installation of untrusted dependencies until a patch is applied.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1766
ALT-PU-2022-1775
BIT-COMPOSER-2021-41116
CVE-2021-41116
GHSA-FRQG-7G38-6GCF
OPENSUSE-SU-2022:0132-1
OPENSUSE-SU-2024:11617-1
OPENSUSE-SU-2024:11874-1

Affected Products

Alt Linux
Composer