PT-2024-4387 · Composer+5 · Composer+5

Shaqpl

·

Published

2024-06-10

·

Updated

2026-04-14

·

CVE-2024-35242

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Composer versions prior to 2.2.24 and 2.7.7
Description The issue is related to the composer install command running inside a git/hg repository with specially crafted branch names, which can lead to command injection. This requires cloning untrusted repositories.
Recommendations For versions prior to 2.2.24, update to version 2.2.24 for 2.2 LTS. For versions prior to 2.7.7, update to version 2.7.7 for mainline. As a temporary workaround, avoid cloning potentially compromised repositories.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-04880
BIT-COMPOSER-2024-35242
CVE-2024-35242
DLA-3838-1
DSA-5715-1
DSA-5715-2
GHSA-V9QV-C7WM-WGMF
OPENSUSE-SU-2024:14040-1
OPENSUSE-SU-2024_2106-1
OPENSUSE-SU-2024_2107-1
SUSE-SU-2024:2106-1
SUSE-SU-2024:2107-1
SUSE-SU-2026:1970-1
USN-7603-1

Affected Products

Astra Linux
Composer
Linuxmint
Red Os
Suse
Ubuntu