CVE-2023-43655

Name
CVE-2023-43655
Description
Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a php file may be subject to a remote code execution vulnerability if PHP also has `register_argc_argv` enabled in php.ini. Versions 2.6.4, 2.2.22 and 1.10.27 patch this vulnerability. Users are advised to upgrade. Users unable to upgrade should make sure `register_argc_argv` is disabled in php.ini, and avoid publishing composer.phar to the web as this is not best practice.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/composer/composer/commit/955a48e6319c8962e5cd421b07c00ab3c728968c
MISC https://github.com/composer/composer/security/advisories/GHSA-jm6m-4632-36hf
MISC https://github.com/composer/composer/commit/95e091c921037b7b6564942845e7b738f6b95c9c
MISC https://github.com/composer/composer/commit/4fce14795aba98e40b6c4f5047305aba17a6120d
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KFOPGPW2KS37O3KJWBRGTUWHTXCQXBS2/
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7AWYAUZNH565NWPIKGEIYBWHYNM5JGAE/
MISC https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/66H2WKFUO255T3BZTL72TNYJYH2XM5FG/
security-advisories@github.com https://lists.debian.org/debian-lts-announce/2024/03/msg00030.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:getcomposer:composer:*:*:*:*:*:*:*:* composer >= 2.3.0 < 2.6.4
cpe:2.3:a:getcomposer:composer:*:*:*:*:*:*:*:* composer >= 2.0.0 < 2.2.21
cpe:2.3:a:getcomposer:composer:*:*:*:*:*:*:*:* composer >= None < 1.10.27

Vulnerable and fixed packages

Source package Branch Version Maintainer Status