CVE-2021-41116

Name
CVE-2021-41116
Description
Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. The issue has been resolved in composer versions 1.10.23 and 2.1.9. There are no workarounds for this issue.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/composer/composer/commit/ca5e2f8d505fd3bfac6f7c85b82f2740becbc0aa
CONFIRM https://github.com/composer/composer/security/advisories/GHSA-frqg-7g38-6gcf
CONFIRM https://www.tenable.com/security/tns-2022-09

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:getcomposer:composer:*:*:*:*:*:*:*:* composer >= None < 1.10.23
cpe:2.3:a:getcomposer:composer:*:*:*:*:*:*:*:* composer >= 2.0.0 < 2.1.9

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
composer 3.14-community 2.1.9-r0 Dave Hall <skwashd@gmail.com> fixed